UAT-7290
· Published 08/01/2026 19:00 · Modified 08/01/2026 19:00
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 08/01/2026 19:00
- Modified
- 08/01/2026 19:00
- Updated at
- 08/01/2026 19:00
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 18 attack patterns (mitre), 8 malware, 1 sectors, 3 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
8 Malwares 3 Observables 1 APT
Attack patterns (MITRE) (18)
-
T1190 usesExploit Public-Facing Application MITRE
-
T1057 usesProcess Discovery MITRE
-
T1083 usesFile and Directory Discovery MITRE
-
T1110 usesBrute Force MITRE
-
T1078 usesValid Accounts MITRE
-
T1102 usesWeb Service MITRE
-
T1572 usesProtocol Tunneling MITRE
-
T1021.004 usesSSH MITRE
-
T1055 usesProcess Injection MITRE
-
T1036 usesMasquerading MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1133 usesExternal Remote Services MITRE
Malware (8)
-
RedLeaves usesFamily The MITRE Corporation Confidence 100
[RedLeaves](https://attack.mitre.org/software/S0153) is a malware family used by [menuPass](https://attack.mitre.org/groups/G0045). The code overlaps with [PlugX](https://attack.mitre.org/software/S0013) and may be based upon the open source tool Trochilus. (Citation: PWC Cloud Hopper Technical…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Bulbature usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RushDrop usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RedLeaves - S0153 usesFamily
-
DriveSwitch usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SilentRaid usesFamily
-
ShadowPad - S0596 usesFamily
-
POISONPLUG.SHADOW usesFamily
Sectors (1)
-
Telecommunications targets
Indicators (3)
-
stix 100/100· Valid until 05/01/2027 · Source: AlienVault
-
stix 100/100· Valid until 24/08/2026 · Source: AlienVault
-
stix 100/100· Valid until 24/08/2026 · Source: AlienVault