STEADY#URSA
· Published 21/12/2025 03:06 · Modified 21/12/2025 03:06
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 03:06
- Modified
- 21/12/2025 03:06
- Updated at
- 21/12/2025 03:06
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 10 attack patterns (mitre), 1 malware, 1 countries, 44 indicators
Description
No description.
Marking (TLP)
TLP:GREEN
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (10)
-
T1091 usesReplication Through Removable Media MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
T1070.004 usesFile Deletion MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1132.001 usesStandard Encoding MITRE
-
T1573 usesEncrypted Channel MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1059.001 usesPowerShell MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1204.001 usesMalicious Link MITRE
Malware (1)
-
SUBTLE-PAWS uses
Countries (1)
-
Ukraine targets
Indicators (44)
-
2f0375bb6a732010d0082f0f44f74d6a641e0a61c9f77d7922a15597cda6a1cdindicates -
5e7aad698dc49213ce6c9a1b2dcfccc3f42769855d5169d41baf99b46d405ad0indicates -
8102995258f1d800a76273213ae57b3a320cbafed491c101db5eb7b191ce53d7indicates -
462be856bf70bc25df2a694825d99b97453f117100a3309df3c03b1fc60eaa61indicates -
ec6283e87abc73cdf0af2120a77ea3140904b261d61782369b9a25431aee9ebfindicates -
6edc9b3ff9f69e86919d80b513e7ca4c93ac0dc03d6e40f85a8703ff49da2758indicates -
3063d671609088bb518ff69fdec337edd1ba5626bd427e03ed8d9d0f8ea4f14findicates -
17752b3f3b452acaf372108cc233ca67790ff62716916a9b84b4e3ef31e89883indicates -
5302e764a9638d86f787137ed02d6c59a4e1e6aa2e7bee27ec91653c83e3127aindicates -
61370d0ac56f73321c11876424ec75e2740d6910ff53b0791f0560c72d85b330indicates -
6dded7fc8b22bfce6f7c548d75b20f01586d348982788626178d48c72d705e26indicates -
b257088c0d3ca65f3a3bda1b8cecf942d0967f3591e182ec32474737ab6bf3c6indicates