Void Blizzard
· Published 21/12/2025 13:54 · Modified 21/12/2025 13:54
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 13:54
- Modified
- 21/12/2025 13:54
- Updated at
- 21/12/2025 13:54
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 38 attack patterns (mitre), 3 malware, 14 sectors, 2 countries, 36 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 Observables 1 APT
-
3 MITREs 2 Malwares 3 Observables 1 APT
Attack patterns (MITRE) (38)
-
T1562 usesImpair Defenses MITRE
-
T1056.001 usesKeylogging MITRE
-
T1567 usesExfiltration Over Web Service MITRE
-
T1071.001 usesWeb Protocols MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1573 usesEncrypted Channel MITRE
-
T1566 usesPhishing MITRE
-
T1083 usesFile and Directory Discovery MITRE
-
T1074.001 usesLocal Data Staging MITRE
-
T1048 usesExfiltration Over Alternative Protocol MITRE
-
T1530 usesData from Cloud Storage MITRE
Malware (3)
-
DRILLAPP usesFamily
-
Evilginx usesFamily
-
AzureHound usesFamily
Sectors (14)
-
Media targets
-
Healthcare targets
-
Education targets
-
Energy targets
-
Transportation targets
-
Defense targets
-
Technology targets
-
Government targets
-
Finance targets
-
Telecommunications targets
-
NGO targets
-
Information Technologies Consulting targets
Countries (2)
-
Ukraine targets
-
United States of America targets
Indicators (36)
-
352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81indicates -
5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672indicates -
21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26indicates -
fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6indicates -
801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9indicates -
51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876eindicates -
outlook-office.micsrosoftonline.comindicates -
a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672indicates -
6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8bindicates