TA558
· Published 20/12/2025 21:56 · Modified 20/12/2025 21:56
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:56
- Modified
- 20/12/2025 21:56
- Updated at
- 20/12/2025 21:56
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 5 attack patterns (mitre), 6 malware, 7 sectors, 2 countries, 93 indicators, 2 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
1 CVE 2 Malwares 74 Observables 1 APT
Attack patterns (MITRE) (5)
Malware (6)
-
Agent Tesla - S0331 usesFamily
-
Revenge RAT - S0379 usesFamily
-
LV usesThe MITRE Corporation Confidence 100
[njRAT](https://attack.mitre.org/software/S0385) is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.(Citation: Fidelis njRAT June 2013)
First seen 01/01/1970 · Last seen 16/11/5138 · -
Remcos usesFamily
-
Ozone RAT usesFamily
-
Loda uses
Sectors (7)
-
Hotel targets
-
Manufacturing targets
-
Finance targets
-
Culture targets
-
Government targets
-
Transportation targets
-
Hospitality targets
Countries (2)
-
Belarus targets
-
Russian Federation targets
Indicators (93)
-
eecb89aaf97fa8333c2c56c16e3905b2b2764271d7f7944bc71a8aba64d2906cindicates -
041c9c4e5242464f8661c6f611da14041447b368e7ff669e5de89e9f805ba486indicates -
akcalogistics.shopindicates -
bc46b7b44928f6ad586d787db33f53ed962aab72441a5518efb3e971d36a40e2indicates -
www.autosmtp.comindicates -
http://corporated.com/tur/turismo.jpgindicates -
maximum.icuindicates -
383ee0319fade807fd02f12a92d4f2b98ba7137f27212b996f3cc9bd88f278acindicates -
http://cdtmaster.com.br/DadosDaReserva.docindicates -
[email protected]indicates -
111234cdt.ddns.netindicates -
8d12cfdb1376c99139b8dba94a0c02357bf7652b763d6313d70dde912266905findicates
Vulnerabilities (CVE) (2)
7.8
High
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 11/07/2017
- Modified
- 22/04/2026
7.8
High
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
- Attack vector
- Local
- Complexity
- Low
- Published
- 15/11/2017
- Modified
- 29/05/2026