SHADOW-EARTH-066, Earth Dahu
· Published 09/06/2026 11:00 · Modified 09/06/2026 11:00
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 09/06/2026 11:00
- Modified
- 09/06/2026 11:00
- Updated at
- 09/06/2026 11:00
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 16 attack patterns (mitre), 2 malware, 2 sectors, 1 countries, 53 indicators, 3 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
AlienVault Confidence 100 3 CVEs 16 MITREs 2 Malwares 53 IOCs 53 Observables 1 APTPublished 08/06/2026 12:30 · Modified 09/06/2026 09:00 · threat-report
Attack patterns (MITRE) (16)
-
T1555.003 usesCredentials from Web Browsers
-
T1564.004 usesNTFS File Attributes
-
T1071.001 usesWeb Protocols
-
T1573.001 usesSymmetric Cryptography
-
T1059.001 usesPowerShell
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1204.002 usesMalicious File
-
T1539 usesSteal Web Session Cookie
-
T1027 usesObfuscated Files or Information
-
T1005 usesData from Local System
-
T1485 usesData Destruction
-
T1566.001 usesSpearphishing Attachment
-
T1041 usesExfiltration Over C2 Channel
-
T1036 usesMasquerading
-
T1497 usesVirtualization/Sandbox Evasion
-
T1070.004 usesFile Deletion
Malware (2)
-
GammaSteel usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
GIFTEDCROOK usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
Sectors (2)
- Government targets
- Defense targets
Countries (1)
- Ukraine targets
Indicators (53)
-
378809699c7252dc38b31969b9cc40858397759f15d6e418246dfaba9088fdd1indicates -
3d371ef71e40c34a75c168d4647db096c2f386499d99a88d4e16b63cd4acda25indicates -
65c053030558b4a3588e2590c5c4961a9912180b731686deb3f4c831e765a095indicates -
4e21c4c97aeb391473ee1e44961676f32de2ee8b56ecb136c1d8081df97c3db4indicates -
7200a9f1e1ea51b66ab9c9274e9d8f805633179634e8ff4dcb8ef82bc02518dfindicates -
38.225.209.122indicates -
https://136.0.141.41:9580/rcv/indicates -
718465f44c0680740fb61790eda3d2f4c5218c9de0c560299c580fa1602dc9c7indicates -
https://166.0.132.237:7044/rcv/indicates -
77963398e2c5c2fdf9d28d9c5f9c2791cfbf422ba02225e01635dd7f5b31eff8indicates -
23.26.237.80indicates -
136.0.141.138indicates -
d1d26b0f68e26ac591848796aeef7b9c766442bbff47af8823f9b23d1b588836indicates -
f668bd551859007cf2cc2a62bf0bf5414870a04e9782590c9bf85c849ddb308bindicates -
507b2fcdae058cebbd550965b90c44e878d7a2463058c846eeb68f0dc1b48edaindicates -
1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953indicates -
194.58.66.82indicates -
8150b2b39fa62fa2de177ed8526c621a3581c0eb481dd9740fc5894ce2b7c13bindicates -
68bafc624a4c0d11ef7a949c0077c704aa5ba0a3205fe5b62d29b727b46ccfe4indicates -
ce78748acd8e9be741b143ad716d735dc682bd5a010427a199744b81456f8e35indicates -
2a8ea9f1ad8936fb302243faa64b91c5767df411923715cbdb1a869e3bfd7e6dindicates -
38.225.209.229indicates -
136.0.141.41indicates -
37b42a83715f7a34e00d3458d4f4b6e53b8c95372677ce020a2e38e80e60ba87indicates -
166.0.132.237indicates -
2d9adb7932b7842dfb0e0f453b87e5d28dd4552094105e6340bad009956d8c2bindicates -
276789b3b946753e9be482219bc4526da2da8772701f3b9d00c74038e2604eceindicates -
c2527a907b209bc4ce911e36b79781ec260f0851eeb466dbeb386d67fec11467indicates -
bf338d88f60c0d352cd0d1b5e4bc6a1d9f1ac8fe1df48516ec0042cafda821e9indicates -
22b07d2af98bb180474c33d93861124bbdf9b5dd7e42a8bddc654310469a9a2cindicates -
6083aac5376b7ca74cc363e0d66f70beaffee543d098c612b820b16fbfb0aa52indicates -
astrocaf.comindicates -
5d164b6d74dae9fe3022bc3cf453cd8b846e9cdc0cd616246fe620be88e3f1e5indicates -
e9d6938c9980cab735e8fb2eaa082ddc6f5dd7f2ff84d8ece01e8caaefdbb930indicates -
malicious.workers.devindicates -
023c8f8e2a71da2044e3f04ac74c8b3616f417436476cea85222f01119615979indicates -
e08dcb80346ded2bb2393a180e3f2612ed4c2ff0d3842390a5b527d003060212indicates -
3c0330f9f934f86b6b70e108ff279a009b88a4a815acbed4adb3664e322e3e59indicates -
2a6ce2445c096fc5e577a0af513ba6f4fb8a8097764c7df81824a782e07e7f65indicates -
89d20418450b34efe698bd36214100cfa49f60adf1c39a8bc8d65991b1ce2c23indicates -
a717dd74c01fcfce35a28f374e1c6f9ded06d6f7b0cc04618ce9454ad64febb8indicates -
dc5082b07eb994ddee343a4080dce0a9ec2e891e5690654e24ae74ba9eabe422indicates -
https://136.0.141.138:8406/rcv/indicates -
f9d2907d6b1de3078a0f111cc98764a92baf5ebd06cc8ab02637a65eff3b7f3aindicates -
44f6f7ba668fc645129d66353e6f60402822ae929ce54648cae0bba6348a18eaindicates -
7d3ba419751e5ea52b567e1162f6a366bf3d06c44c8956a9f14520e9fb6ed0b1indicates -
82fda6ea769d61aba230c3487787087cec53dd378e22f22a8fb8f0bd5ae83dedindicates -
194.58.66.53indicates -
https://38.225.209.229:9623/rcv/indicates -
joymobile.com.uaindicates -
136.0.141.112indicates -
e6bd725a2af981cd2b5c2217c1d7d906369d8daf48f02023fb73635f9e2b9659indicates -
b01f31c9541579ad34f4e50acafec252eb419f5b1ca98155e0ec84c19d12c9e4indicates
Vulnerabilities (CVE) (3)
CVE-2025-6218
KEV
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
- Published
- 09/12/2025
- Modified
- 21/12/2025
CVE-2018-20250
KEV
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
- Published
- 15/02/2022
- Modified
- 02/06/2026
CVE-2025-8088
KEV
8.8
High
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
- Attack vector
- Network
- Published
- 12/08/2025
- Modified
- 27/05/2026