Twisted Panda
· Published 20/12/2025 19:47 · Modified 20/12/2025 19:47
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 19:47
- Modified
- 20/12/2025 19:47
- Updated at
- 20/12/2025 19:47
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 attack patterns (mitre), 3 malware, 10 sectors, 3 countries, 24 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (8)
-
T1566 usesPhishing MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1574 usesHijack Execution Flow MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1055 usesProcess Injection MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1106 usesNative API MITRE
Malware (3)
-
SPINNER usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Hodur uses
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (10)
-
Aerospace targets
-
Defense ministries (including the military) targets
-
Healthcare targets
-
Transportation targets
-
Manufacturing targets
-
Defense targets
-
Energy targets
-
Avionics targets
-
High-tech targets
-
Healthcare services targets
Countries (3)
-
Russian Federation targets
-
Belarus targets
-
Ukraine targets
Indicators (24)
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of d95bbe8a97d864dc40c9cf845aeb4e9e
· Valid until 23/08/2023 · Source: AlienVault -
636e35705ca1637fa3419e7728592b581be4e5dcindicatesyara 100/100 RevokedDetect an older variant of SPINNER payload used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 1f9a72dc91759cd06a0f05ac4486dda1
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
img.elliotterusties.comindicatesstix 100/100 Revoked· Valid until 02/09/2023 · Source: AlienVault -
f01dd4397c88713e7083cf6a12bdd200caf497a6indicatesyara 100/100 RevokedDetect the obfuscated variant of SPINNER payload used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/07/2022 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault