Twisted Panda
· Published 20/12/2025 19:47 · Modified 20/12/2025 19:47
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 19:47
- Modified
- 20/12/2025 19:47
- Updated at
- 20/12/2025 19:47
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 attack patterns (mitre), 3 malware, 10 sectors, 3 countries, 24 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (8)
-
T1566 usesPhishing MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1574 usesHijack Execution Flow MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1055 usesProcess Injection MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1106 usesNative API MITRE
Malware (3)
-
SPINNER usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Hodur uses
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (10)
-
Aerospace targets
-
Defense ministries (including the military) targets
-
Healthcare targets
-
Transportation targets
-
Manufacturing targets
-
Defense targets
-
Energy targets
-
Avionics targets
-
High-tech targets
-
Healthcare services targets
Countries (3)
-
Russian Federation targets
-
Belarus targets
-
Ukraine targets
Indicators (24)
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked
TEL:MacroLoadLibrary SHA256 of 3855dc19811715e15d9775a42b1a6c55
· Valid until 23/08/2023 · Source: AlienVault -
70237746c55ddb5e7d00602f1e9ba9872931fa67indicatesyara 100/100 RevokedDetect droppers used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
92fe17c33fc9a81f5db9efbfeadfd7a6e4f704e8indicatesyara 100/100 RevokedDetect loader used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 698d1ade6defa07fb4e4c12a19ca309957fb9c40
· Valid until 09/08/2023 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 6d4bf8dd4864f9ac564d3c9661b99190
· Valid until 23/08/2023 · Source: AlienVault -
117a780708817e2eb92a517e2f6cb3d3dcd4d9beindicatesyara 100/100 RevokedDetect the 64bit Loader DLL used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault