Outlaw
· Published 21/12/2025 13:19 · Modified 21/12/2025 13:55
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 13:19
- Modified
- 21/12/2025 13:55
- Updated at
- 21/12/2025 13:55
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 28 attack patterns (mitre), 5 malware, 8 countries, 9 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
5 MITREs 3 Malwares 1 APTPublished 29/04/2025 16:27 · Modified 29/04/2025 21:52
-
11 MITREs 4 Malwares 87 Observables 1 APTPublished 03/04/2025 22:07 · Modified 04/04/2025 07:26
Attack patterns (MITRE) (28)
-
T1071 usesApplication Layer Protocol
-
T1059 usesCommand and Scripting Interpreter
-
T1496 usesResource Hijacking
-
T1048 usesExfiltration Over Alternative Protocol
-
T1070.004 usesFile Deletion
-
T1105 usesIngress Tool Transfer
-
T1098.004 usesSSH Authorized Keys
-
T1005 usesData from Local System
-
T1021.004 usesSSH
-
T1057 usesProcess Discovery
-
T1098 usesAccount Manipulation
-
T1053.003 usesCron
-
T1210 usesExploitation of Remote Services
-
T1087 usesAccount Discovery
-
T1564.001 usesHidden Files and Directories
-
T1053 usesScheduled Task/Job
-
T1222 usesFile and Directory Permissions Modification
-
T1110 usesBrute Force
-
T1041 usesExfiltration Over C2 Channel
-
T1033 usesSystem Owner/User Discovery
-
T1571 usesNon-Standard Port
-
T1027.002 usesSoftware Packing
-
T1049 usesSystem Network Connections Discovery
-
T1059.004 usesUnix Shell
-
T1552 usesUnsecured Credentials
-
T1082 usesSystem Information Discovery
-
T1489 usesService Stop
-
T1027 usesObfuscated Files or Information
Malware (5)
-
OUTLAW usesFamilyPublished 29/04/2025 16:27 · Modified 29/04/2025 16:27
-
XMRig usesFamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
-
BLITZ usesFamilyPublished 03/04/2025 22:07 · Modified 03/04/2025 22:07
-
STEALTH SHELLBOT usesFamilyPublished 03/04/2025 22:07 · Modified 03/04/2025 22:07
-
Dota usesFamilyPublished 29/04/2025 16:27 · Modified 29/04/2025 16:27
Countries (8)
- Taiwan targets
- United States of America targets
- Italy targets
- Brazil targets
- Canada targets
- Singapore targets
- Thailand targets
- Germany targets
Indicators (9)
-
e13c9eb1aa911b21615c7496f5c0f14e133d96d20e7d7f24e97e8519d50a17d1indicates -
c3efbd6b5e512e36123f7b24da9d83f11fffaf3023d5677d37731ebaa959dd27indicates -
5a0121f8dd9f391762c7f6dd525641000ed64f8a5669f14b67e56b387069d4feindicates -
083e706194a92aa96825007dbcbaff4f64a0200c77a70cde17974be6716886e6indicates -
75d868b93ae3064ada769a4b2035b87e8eab6ade43aea8ffff8199fc4a66f849indicates -
5a3291a81d961053fcb5495973c5aa9755ae4b54a689947914489f7fb4fe7f71indicates -
0e8472f2005560c6f4db4e5aef39e5d35185b35c67f70a27c8b3dcb242eed25eindicates -
ed9330e1594e73097dc6c8bf9f157de0d3799171a1967aaa43f9cd8629092f07indicates -
4cce28bb4390e1a653b09e9bf03aaf7867f00c3cd94b9d52f4775719112708c9indicates