TA558
· Published 20/12/2025 21:56 · Modified 20/12/2025 21:56
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:56
- Modified
- 20/12/2025 21:56
- Updated at
- 20/12/2025 21:56
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 5 attack patterns (mitre), 6 malware, 7 sectors, 2 countries, 93 indicators, 2 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
1 CVE 2 Malwares 74 Observables 1 APT
Attack patterns (MITRE) (5)
Malware (6)
-
Agent Tesla - S0331 usesFamily
-
Revenge RAT - S0379 usesFamily
-
LV usesThe MITRE Corporation Confidence 100
[njRAT](https://attack.mitre.org/software/S0385) is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.(Citation: Fidelis njRAT June 2013)
First seen 01/01/1970 · Last seen 16/11/5138 · -
Remcos usesFamily
-
Ozone RAT usesFamily
-
Loda uses
Sectors (7)
-
Hotel targets
-
Manufacturing targets
-
Finance targets
-
Culture targets
-
Government targets
-
Transportation targets
-
Hospitality targets
Countries (2)
-
Belarus targets
-
Russian Federation targets
Indicators (93)
-
www.metabaseq.comindicates -
http://tt.vg/IsjCXindicates -
[email protected]indicates -
91a14852328b337a5aa1046bc7f92448f2c0a3c2ec5a8a76729de68521fa2a39indicates -
baltictransline.storeindicates -
[email protected]indicates -
18b8e4782b590141ff10ecde5b76bd1e35d99890a517741ac71408a478a56a81indicates -
success20.hopto.orgindicates -
3030pp.hopto.orgindicates -
https://www.autosmtp.comindicates -
googledrives.ddns.netindicates -
http://hypemediardf.com.pl/css/css.docindicates
Vulnerabilities (CVE) (2)
7.8
High
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 11/07/2017
- Modified
- 22/04/2026
7.8
High
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
- Attack vector
- Local
- Complexity
- Low
- Published
- 15/11/2017
- Modified
- 29/05/2026