Roaming Mantis
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:32
- Modified
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 18 attack patterns (mitre), 2 intrusion sets (apt), 5 sectors, 15 countries, 39 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (18)
Intrusion sets (APT) (2)
-
Roaming Mantis usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (5)
-
Universities targets
-
Technology targets
-
Defense targets
-
Government targets
-
Road transport targets
Countries (15)
-
Iran, Islamic Republic of targets
-
United States of America targets
-
Cyprus targets
-
Afghanistan targets
-
Spain targets
-
Korea, Republic of targets
-
India targets
-
Turkey targets
-
Hong Kong targets
-
Bangladesh targets
-
France targets
-
Pakistan targets
Indicators (39)
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 56470e113479eacda081c2eeead153bf
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of b3a8c88297daecdb9b0ac54a3c107797
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
LZMA SHA256 of d1c652b4192857cb08907f0ba1790976
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 11fdc0be9d85b4ff1faf5ca33cc272ed
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 9fd35bad075c2c70678c65c788b91bc3 SHA256 of 9fd35bad075c2c70678c65c788b91bc3
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100
Other:Malware-gen\ [Trj] SHA256 of 1f254dd0b85edd7e11339681979e3ad6
· Valid until 01/09/2026 · Source: AlienVault -
stix 100/100 Revoked
Doc.Dropper.Agent-6960083-0 SHA256 of 7a73a2261e20bdb8d24a4fb252801db7
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
LZMA SHA256 of 78d42cedb0c012c62ef5be620c200d43 SHA256 of 78d42cedb0c012c62ef5be620c200d43
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 183ad96b931733ad37bb627a958837db
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
Other:Malware-gen\ [Trj] SHA256 of 9121f1c13955506e33894ffd780940cd
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
Win64:Evo-gen\ [Susp] SHA256 of ca6658852480c70118feba12eb1be880 SHA256 of ca6658852480c70118feba12eb1be880
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
stack_string SHA256 of 2b02465b65024336a9e15d7f34c1f5d9 SHA256 of 2b02465b65024336a9e15d7f34c1f5d9
· Valid until 15/07/2024 · Source: AlienVault