YoroTrooper
· Published 21/12/2025 00:02 · Modified 21/12/2025 00:02
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 00:02
- Modified
- 21/12/2025 00:02
- Updated at
- 21/12/2025 00:02
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 14 attack patterns (mitre), 5 malware, 6 sectors, 5 countries, 170 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (14)
-
T1176 usesSoftware Extensions
-
T1505 usesServer Software Component
-
T1056 usesInput Capture
-
T1547 usesBoot or Logon Autostart Execution
-
T1027 usesObfuscated Files or Information
-
T1102 usesWeb Service
-
T1003 usesOS Credential Dumping
-
T1496 usesResource Hijacking
-
T1059 usesCommand and Scripting Interpreter
-
T1566 usesPhishing
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1036 usesMasquerading
Malware (5)
-
AveMaria usesFamilyPublished 26/11/2025 14:09 · Modified 26/11/2025 14:09
- WarzoneRAT
-
Meterpreter usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
- Stink
- LodaRAT
Sectors (6)
- Government targets
- Nuclear power (civilian use) targets
- Telecommunications targets
- Energy targets
- Ministries of foreign affairs targets
- Transportation targets
Countries (5)
- Türkiye targets
- Kyrgyzstan targets
- Kazakhstan targets
- Tajikistan targets
- Azerbaijan targets
Indicators (170)
-
sts.mfa.gov.tr.mypolicy.topindicates -
fd7fe71185a70f281545a815fce9837453450bb29031954dd2301fe4da99250dindicates -
f2a17d140efcf94800c6dc4a2454d0f8320a9e41c04145fbbeeea84ea0321d74indicates -
account.mail.ru.sigriup.siteindicates -
a26e8014e67005f1516af849ea4534db2d7a0c8c8b7fffd7890111363439c3f7indicates -
http://tpp.tj/T/file.jsindicates -
1b82739880e1851d032b09de787033bd19135c8496124cd505b32afe4212b7b0indicates -
http://tpp.tj/main.exeindicates -
http://tpp.tj/T/rat.phpindicates -
http://89.22.233.149/Spisok_sotrudnikov_1_chast.exeindicates -
http://45.61.136.175/indicates -
http://redirect.az-link.email/indicates