Roaming Mantis
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:32
- Modified
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 18 attack patterns (mitre), 2 intrusion sets (apt), 5 sectors, 15 countries, 39 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (18)
-
T1049 usesSystem Network Connections Discovery MITRE
-
T1021 usesRemote Services MITRE
-
T1195 usesSupply Chain Compromise MITRE
-
T1055 usesProcess Injection MITRE
-
Multi-Stage Channels usesT1104 MITRE
-
T1569 usesSystem Services MITRE
-
T1115 usesClipboard Data MITRE
-
T1566 usesPhishing MITRE
-
T1102 usesWeb Service MITRE
-
TA0008 uses
-
T1041 usesExfiltration Over C2 Channel MITRE
-
T1546 usesEvent Triggered Execution MITRE
Intrusion sets (APT) (2)
-
Roaming Mantis usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (5)
-
Universities targets
-
Technology targets
-
Defense targets
-
Government targets
-
Road transport targets
Countries (15)
-
Iran, Islamic Republic of targets
-
United States of America targets
-
Cyprus targets
-
Afghanistan targets
-
Spain targets
-
Korea, Republic of targets
-
India targets
-
Turkey targets
-
Hong Kong targets
-
Bangladesh targets
-
France targets
-
Pakistan targets
Indicators (39)
-
stix 100/100 Revoked
stack_string SHA256 of eb2dc282ad3ab29c1853d4f6d09bec4f SHA256 of eb2dc282ad3ab29c1853d4f6d09bec4f
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
LZMA SHA256 of e9d89d1364bd73327e266d673d6c8acf
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 9ea365c1714eb500e5f4a749a3ed0fe7
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 25b37c971fd7e9e50e45691aa86e5f0a
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
Win64:Trojan-gen SHA256 of cd5357d1045948ba62710ad8128ae282
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
Win32:Evo-gen\ [Susp] SHA256 of 64e5acf43613cd10e96174f36cb1d680
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 4c239a926676087e31d82e79e838ced1
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 2efbe6901fc3f479bc32aaf13ce8cf12
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
Win64:Trojan-gen SHA256 of 1bd0ca304cdecfa3bd4342b261285a72
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of e7aa0237fc3db67a96ebd877806a2c88
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100
Other:Malware-gen\ [Trj] SHA256 of 65df11dea0c1d0f0304b376787e65ccb
· Valid until 01/09/2026 · Source: AlienVault -
stix 100/100 Revoked
TELPER:Trojan:Win32/ShortWick.B!dha SHA256 of 706e55af384e1d8483d2748107cbd57c
· Valid until 15/07/2024 · Source: AlienVault