Laundry Bear
· Published 21/12/2025 16:51 · Modified 21/12/2025 16:51
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 16:51
- Modified
- 21/12/2025 16:51
- Updated at
- 21/12/2025 16:51
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 22 attack patterns (mitre), 1 malware, 3 sectors, 3 countries, 79 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
12 MITREs 1 Malware 28 Observables 1 APTPublished 17/03/2026 11:01 · Modified 17/03/2026 11:17
-
1 MITRE 1 APTPublished 29/08/2025 12:19 · Modified 29/08/2025 15:19
Attack patterns (MITRE) (22)
-
T1105 usesIngress Tool Transfer
-
T1033 usesSystem Owner/User Discovery
-
T1059.007 usesJavaScript
-
T1583.001 usesDomains
-
T1057 usesProcess Discovery
-
T1204.001 usesMalicious Link
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1132.001 usesStandard Encoding
-
T1074.001 usesLocal Data Staging
-
T1056.001 usesKeylogging
-
T1071.001 usesWeb Protocols
-
T1589.002 usesEmail Addresses
-
T1566 usesPhishing
-
T1005 usesData from Local System
-
T1102 usesWeb Service
-
T1608.001 usesUpload Malware
-
T1113 usesScreen Capture
-
T1082 usesSystem Information Discovery
-
T1568 usesDynamic Resolution
-
T1584.001 usesDomains
-
T1083 usesFile and Directory Discovery
-
T1078 usesValid Accounts
Malware (1)
-
DRILLAPP usesFamilyPublished 17/03/2026 11:01 · Modified 17/03/2026 11:01
Sectors (3)
- Government targets
- Defense targets
- NGO targets
Countries (3)
- Netherlands targets
- Ukraine targets
- United States of America targets
Indicators (79)
-
login.walshhgroup.comindicates -
21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26indicates -
aficors.comindicates -
it-sharepoint.comindicates -
microffice.orgindicates -
enticator-secure.comindicates -
bidscale.netindicates -
micsrosoftonline.comindicates -
auth.enticator-secure.comindicates -
myspringbank.comindicates -
mail-forgot.comindicates -
refundes.netindicates -
css.mpgc10.comindicates -
51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876eindicates -
walshhgroup.comindicates -
801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9indicates -
propescom.comindicates -
outlook-office.micsrosoftonline.comindicates -
886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14indicates -
a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672indicates -
ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3indicates -
32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715indicates -
e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341indicates -
deloittesharepoint.comindicates -
defraudatubanco.comindicates -
ebsumrnit.euindicates -
6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8bindicates -
onionmail.comindicates -
static.it-sharepoint.comindicates -
ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759dindicates -
ns1.it-sharepoint.comindicates -
fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6indicates -
app-v4-mybos.comindicates -
link.walshhgroup.comindicates -
redronesolutions.cloudindicates -
ebsurnmit.euindicates -
m-365-app.comindicates -
ebsum.euindicates -
ebsummit.euindicates -
email.ebsumrnit.euindicates -
2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3findicates -
352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81indicates -
6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaaeindicates -
login.maidservant.shopindicates -
ebsummt.euindicates -
portal-microsoftonline.comindicates -
5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672indicates -
f0f3db24af0132755c8a0068dde433f857d8639020deb2817d52d3a1d5d99f35indicates -
usembassyservice.comindicates -
bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056indicates -
ebsummits.euindicates -
188.137.228.162indicates -
max-linear.comindicates -
ourbelovedsainscore.spaceindicates -
aoc-gov.usindicates -
weblogmail.liveindicates -
x9a7lm02kqaccountprotectionaccountsecuritynoreply.comindicates -
miscrsosoft.comindicates -
avsgroup.auindicates -
remerelli.comindicates -
ebsumlts.euindicates -
ads.it-sharepoint.comindicates -
b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28indicates -
ups-mail.deliveryindicates -
ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630indicates -
8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05indicates -
80.89.224.13indicates -
993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81cindicates -
107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3indicates -
66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181indicates -
9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1indicates -
ebsummlt.euindicates -
nticator.comindicates -
spidergov.orgindicates -
teamsupportonline.topindicates -
eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3indicates -
maidservant.shopindicates -
c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aaindicates -
76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746indicates