SPINNER
AlienVault
· Published 20/12/2025 19:32 · Modified 20/12/2025 19:47
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:32
- Modified
- 20/12/2025 19:47
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 8 attack patterns (mitre), 1 intrusion sets (apt), 10 sectors, 3 countries, 24 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (8)
-
T1055 usesProcess Injection MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1106 usesNative API MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1566 usesPhishing MITRE
-
T1574 usesHijack Execution Flow MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1027 usesObfuscated Files or Information MITRE
Intrusion sets (APT) (1)
-
Twisted Panda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (10)
-
High-tech targets
-
Avionics targets
-
Healthcare targets
-
Defense targets
-
Air transport targets
-
Transportation targets
-
Manufacturing targets
-
Defense ministries (including the military) targets
-
Energy targets
-
Healthcare services targets
Countries (3)
-
Russian Federation targets
-
Ukraine targets
-
Belarus targets
Indicators (24)
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of d95bbe8a97d864dc40c9cf845aeb4e9e
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked
TEL:MacroLoadLibrary SHA256 of 3855dc19811715e15d9775a42b1a6c55
· Valid until 23/08/2023 · Source: AlienVault -
117a780708817e2eb92a517e2f6cb3d3dcd4d9beindicatesyara 100/100 RevokedDetect the 64bit Loader DLL used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
f01dd4397c88713e7083cf6a12bdd200caf497a6indicatesyara 100/100 RevokedDetect the obfuscated variant of SPINNER payload used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 23/08/2023 · Source: AlienVault
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 1f9a72dc91759cd06a0f05ac4486dda1
· Valid until 23/08/2023 · Source: AlienVault -
70237746c55ddb5e7d00602f1e9ba9872931fa67indicatesyara 100/100 RevokedDetect droppers used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/07/2022 · Source: AlienVault
-
636e35705ca1637fa3419e7728592b581be4e5dcindicatesyara 100/100 RevokedDetect an older variant of SPINNER payload used by TwistedPanda
· Valid until 23/08/2023 · Source: AlienVault