Gleaming Pisces
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 04/05/2026 16:59
- Updated at
- 04/05/2026 16:59
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 30 attack patterns (mitre), 6 malware, 5 sectors, 18 indicators, 10 vulnerabilities (cve), 1 campaign
Aliases
UNC1720 UNC4736 Citrine Sleet AppleJeus
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
3 CVEs 22 MITREs 5 Malwares 16 Observables 1 APTPublished 04/05/2026 06:08 · Modified 04/05/2026 14:59
Attack patterns (MITRE) (30)
-
T1105 usesIngress Tool Transfer
-
T1204.002 usesMalicious File
-
Financial Theft uses
-
T1014 usesRootkit
-
T1132 usesData Encoding
-
T1195.002 usesCompromise Software Supply Chain
-
T1083 usesFile and Directory Discovery
-
T1553 usesSubvert Trust Controls
-
T1059 usesCommand and Scripting Interpreter
-
T1573 usesEncrypted Channel
-
T1543 usesCreate or Modify System Process
-
T1588.002 usesTool
-
T1106 usesNative API
-
T1005 usesData from Local System
-
T1176 usesSoftware Extensions
-
T1027 usesObfuscated Files or Information
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1195 usesSupply Chain Compromise
-
T1036 usesMasquerading
-
T1059.004 usesUnix Shell
-
T1102 usesWeb Service
-
T1496 usesResource Hijacking
-
T1082 usesSystem Information Discovery
-
T1566 usesPhishing
-
T1059.006 usesPython
-
T1068 usesExploitation for Privilege Escalation
-
T1041 usesExfiltration Over C2 Channel
-
T1071.001 usesWeb Protocols
-
T1543.001 usesLaunch Agent
-
T1571 usesNon-Standard Port
Malware (6)
-
Kaolin usesFamilyPublished 02/09/2024 20:46 · Modified 02/09/2024 20:46
-
BADCALL - S0245 usesFamilyPublished 04/05/2026 06:08 · Modified 04/05/2026 06:08
-
kupayupdate_stage2 usesFamilyPublished 04/05/2026 06:08 · Modified 04/05/2026 06:08
-
PondRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:46 · Modified 29/05/2026 12:20
-
AppleJeus - S0584 usesFamilyPublished 04/05/2026 06:08 · Modified 04/05/2026 06:08
-
POOLRAT usesFamilyPublished 25/05/2026 13:00 · Modified 25/05/2026 13:00
Sectors (5)
- Entertainment industry targets
- Technology targets
- Financial organizations targets
- Government targets
- Finance targets
Indicators (18)
-
bfd74b4a1b413fa785a49ca4a9c0594441a3e01983fc7f86125376fdbd4acf6bindicates -
cbf4cfa2d3c3fb04fe349161e051a8cf9b6a29f8af0c3d93db953e5b5dc39c86indicates -
www.talesseries.comindicates -
3c8dbfcbb4fccbaf924f9a650a04cb4715f4a58d51ef49cc75bfcef0ac258a3eindicates -
0b5db31e47b0dccfdec46e74c0e70c6a1684768dbacc9eacbb4fd2ef851994c7indicates -
jdkgradle.comindicates -
http://www.talesseries.com/write.phpindicates -
rebelthumb.netindicates -
5c907b722c53a5be256dc5f96b755bc9e0b032cc30973a52d984d4174bace456indicates -
bce1eb513aaac344b5b8f7a9ba9c9e36fc89926d327ee5cc095fb4a895a12f80indicates -
f3b0da965a4050ab00fce727bb31e0f889a9c05d68d777a8068cfc15a71d3703indicates -
91eaf215be336eae983d069de16630cc3580e222c427f785e0da312d0692d0fdindicates -
5e40d106977017b1ed235419b1e59ff090e1f43ac57da1bb5d80d66ae53b1df8indicates -
973f7939ea03fd2c9663dafc21bb968f56ed1b9a56b0284acf73c3ee141c053cindicates -
weinsteinfrog.comindicates -
voyagorclub.spaceindicates -
rgedist.comindicates -
http://rgedist.com/sfxl.phpindicates
Vulnerabilities (CVE) (10)
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys …
- Attack vector
- Local
- Published
- 04/03/2024
- Modified
- 21/12/2025
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. …
- Attack vector
- Network
- Published
- 26/08/2024
- Modified
- 21/12/2025
Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain …
- Attack vector
- Local
- Published
- 13/08/2024
- Modified
- 21/12/2025
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This …
- Attack vector
- Network
- Published
- 28/05/2024
- Modified
- 21/12/2025
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation …
- Attack vector
- Local
- Published
- 13/08/2024
- Modified
- 21/12/2025
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma …
- Attack vector
- NETWORK
- Published
- 29/03/2024
- Modified
- 21/12/2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Campaign (1)
- 3CX Supply Chain Attack attributed-to