SANDWORM_MODE
AlienVault
· Published 23/02/2026 11:19 · Modified 23/02/2026 11:19
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 23/02/2026 11:19
- Modified
- 23/02/2026 11:19
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 18 attack patterns (mitre), 4 indicators, 1 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (18)
-
T1078 usesValid Accounts MITRE
-
T1552.001 usesCredentials In Files MITRE
-
T1574.005 MITRE
-
T1132.001 usesStandard Encoding MITRE
-
T1119 usesAutomated Collection MITRE
-
T1132.002 usesNon-Standard Encoding MITRE
-
T1552.003 usesShell History MITRE
-
T1112 usesModify Registry MITRE
-
T1518.001 usesSecurity Software Discovery MITRE
-
T1056.004 usesCredential API Hooking MITRE
-
T1195 usesSupply Chain Compromise MITRE
-
T1588.002 usesTool MITRE
Indicators (4)
-
stix 100/100 Revoked· Valid until 24/03/2026 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 24/03/2026 · Source: AlienVault
Reports (1)
-
12 MITREs 1 Malware 2 Observables