UNC2565
· Published 20/12/2025 23:28 · Modified 20/12/2025 23:28
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 23:28
- Modified
- 20/12/2025 23:28
- Updated at
- 20/12/2025 23:28
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 11 attack patterns (mitre), 3 malware, 11 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (11)
Malware (3)
-
FONELAUNCH uses
-
Gootloader usesFamily
-
Cobalt Strike usesFamily
Indicators (11)
-
kristinee.comindicatesstix 100/100 Revoked· Valid until 27/11/2023 · Source: AlienVault -
jp.imonitorsoft.comindicatesstix 100/100 Revoked· Valid until 15/05/2024 · Source: AlienVault -
kepw.orgindicatesstix 100/100 Revoked· Valid until 27/11/2023 · Source: AlienVault -
stix 100/100 Revoked
HackTool:Win32/CobaltStrike.A SHA256 of 04746416d5767197f6ce02e894affcc7
· Valid until 05/05/2024 · Source: AlienVault -
kakiosk.adsparkdev.comindicatesstix 100/100 Revoked· Valid until 15/05/2024 · Source: AlienVault -
stix 100/100 Revoked
JS:Dropper-AABB\ [Trj] SHA256 of ab1171752af289e9f85a918845859848
· Valid until 05/05/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of d6220ca85c44e2012f76193b38881185
· Valid until 05/05/2024 · Source: AlienVault -
junk-bros.comindicatesstix 100/100 Revoked· Valid until 27/11/2023 · Source: AlienVault -
lakeside-fishandchips.comindicatesstix 100/100 Revoked· Valid until 27/11/2023 · Source: AlienVault -
d7e7b3881891c00e4785249a07d830cc7c32ace5indicatesyara 100/100 RevokedHunting rule looking for suspicious version information metadata observed in FONELAUNCH samples
· Valid until 05/05/2024 · Source: AlienVault -
jonathanbartz.comindicatesstix 100/100 Revoked· Valid until 27/11/2023 · Source: AlienVault