TA558
· Published 20/12/2025 21:56 · Modified 20/12/2025 21:56
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:56
- Modified
- 20/12/2025 21:56
- Updated at
- 20/12/2025 21:56
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 5 attack patterns (mitre), 6 malware, 7 sectors, 2 countries, 93 indicators, 2 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
1 CVE 2 Malwares 74 Observables 1 APT
Attack patterns (MITRE) (5)
Malware (6)
-
Agent Tesla - S0331 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Revenge RAT - S0379 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LV usesThe MITRE Corporation Confidence 100
[njRAT](https://attack.mitre.org/software/S0385) is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.(Citation: Fidelis njRAT June 2013)
First seen 01/01/1970 · Last seen 16/11/5138 · -
Remcos usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Ozone RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Loda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (7)
-
Hotel targets
-
Manufacturing targets
-
Finance targets
-
Culture targets
-
Government targets
-
Transportation targets
-
Hospitality targets
Countries (2)
-
Belarus targets
-
Russian Federation targets
Indicators (93)
-
4d97a5069b154b2e95af235dd32c82c1bf5b2e4cf2d188067da223f488ebaa48indicates -
isols.coindicates -
0f9a81081fd7ff58c83c78bcfa4735556fd3ad823f917fe28787085f2d309336indicates -
ea17ccf4bf55f23b8a93f8e17e470be440211f463d5b7e01958843c8c160f765indicates -
stix 100/100 Revoked· Valid until 02/11/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 02/11/2025 · Source: AlienVault
-
http://corporated.com/microsoft.txtindicatesstix 100/100 Revoked· Valid until 04/10/2022 · Source: AlienVault -
stix 100/100 Revoked· Valid until 21/11/2023 · Source: AlienVault
-
vervo.latindicates -
079de6fa0a294bbab99ca481e03e5d0360cdfae1ab41ffd7cc37a92d7bcc25a1indicates
Vulnerabilities (CVE) (2)
7.8
High
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 11/07/2017
- Modified
- 22/04/2026
7.8
High
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
- Attack vector
- Local
- Complexity
- Low
- Published
- 15/11/2017
- Modified
- 29/05/2026