Operation SalmonSlalom
· Published 26/02/2025 09:26 · Modified 26/02/2025 10:02
Essential information
- Published
- 26/02/2025 09:26
- Modified
- 26/02/2025 10:02
- Tags
- 2025-02-26 dll sideloading fatalrat gh0st rat moudoor mydoor simayrat zegost
- Related entities
- 160 observables, 23 techniques (mitre), 6 malware, 15 others
Description
A sophisticated cyberattack targeting industrial organizations in the Asia-Pacific region has been uncovered. The attackers utilized legitimate Chinese cloud services and a multi-stage payload delivery framework to evade detection. The campaign, named SalmonSlalom, employed techniques such as native file hosting CDN, public packers for encryption, dynamic C2 address changes, and DLL sideloading. The attack shares similarities with previous campaigns using open-source RATs like Gh0st RAT and FatalRAT, but demonstrates a shift in tactics tailored to Chinese-speaking targets. The malware installation process is complex, involving multiple stages and the use of legitimate applications to disguise malicious activity.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (160)
82.156.145.21681.71.1.1078.217.0.1647.57.68.15743.159.192.19647.106.224.10743.155.73.23543.154.68.19343.154.238.13043.139.35.4243.139.101.1143.138.199.24143.138.176.5206.233.130.14142.193.242.180175.178.96.9175.178.89.24175.178.166.216156.236.67.181154.91.227.32154.39.238.101123.207.8.204139.199.168.63134.122.137.252123.207.79.195123.207.55.60123.207.44.193123.207.35.145123.207.1.145123.207.16.43122.152.231.146120.78.173.89120.79.91.168119.29.219.211114.132.56.175114.132.46.48114.132.121.130111.230.91.145111.230.93.174111.230.45.217111.230.32.52111.230.108.14111.230.10.93107.148.54.105107.148.52.242107.148.52.176106.52.216.112107.148.50.113103.144.29.211103.144.29.1231.12.37.113101.33.243.31154.197.6.103154.206.236.9123.207.58.147119.29.235.38111.230.15.48107.148.50.116107.148.52.241107.148.50.112http://svp7.net:9874/UltraViewer.exehttp://svp7.net:9874/AnyDesk.exehttp://82.156.145.216:6000http://81.71.1.107:6000http://8.217.0.16:6000http://47.106.224.107:6000http://47.57.68.157:8080http://43.159.192.196:6000http://43.154.68.193:6000http://43.154.238.130:8081http://43.154.238.130:6000http://43.139.35.42:6000http://43.138.199.241:6000http://43.139.101.11:6000http://42.193.242.180:6000http://43.138.176.5:6000http://206.233.130.141:6000http://175.178.96.9:8081http://175.178.89.24:6000http://175.178.166.216:6000http://156.236.67.181:6000http://154.91.227.32:6000http://154.39.238.101:6000http://154.206.236.9:6000http://139.199.168.63:6000http://154.197.6.103:6000http://134.122.137.252:6000http://123.207.8.204:6000http://123.207.79.195:6000http://123.207.55.60:6000http://123.207.58.147:6000http://123.207.44.193:6000http://123.207.35.145:6000http://123.207.16.43:6000http://123.207.1.145:6000http://122.152.231.146:6000http://120.79.91.168:6000http://120.78.173.89:6000http://119.29.235.38:6000http://119.29.219.211:6000http://114.132.56.175:6000http://114.132.46.48:6000http://114.132.121.130:6000http://111.230.93.174:8081http://111.230.91.145:8081http://111.230.45.217:8081http://111.230.32.52:6000http://111.230.15.48:8081http://111.230.108.14:6000http://111.230.10.93:6000http://107.148.54.105:6000http://107.148.52.242:6000http://107.148.52.241:6000http://107.148.52.176:6000http://107.148.50.113:6000http://107.148.50.112:6000http://107.148.50.116:6000http://106.52.216.112:6000http://103.144.29.211:6000http://103.144.29.123:6000http://101.33.243.31:82/initialsubmission?windows_version=17134&computer_name=MYTEST:DESKTOP-CROB74Dhttp://101.33.243.31:82http://1.12.37.113:8081nbs2012.novadector.xyz34.kosdage.asia110.kkftodesk110.top109.kkftodesk109.top108.kkftodesk108.top107.kkftodesk107.top106.kkftodesk106.top105.kkftodesk105.top104.kkftodesk104.top102.kkftodesk102.top101.kkftodesk101.topxindajiema.infosvp7.netnovadector.xyzmicrosoftmiddlename.tkmicrosoftupdatesoftware.gacloudservicesdevc.tk0a305ffb2a1d41f6870eac02f9afce89.xyzapi.youkesdt.asiafd1a608a9e1bfcb845f59fa6b89aa6d27511517d4fb42d3f970f7404dc6ef138cb201744a0f50e72ee4fda9298785fa16bfc4bf639a9474457e429278ff376bca996e4c18ae4c4563db0767cb230b24279daeb3f62ee62b061d2ee076d81bdfdabb2cb43caecac0ca2dcba15ee1cdcc4499ffad18c06265de2ac2f811166d976a46b8a14d6e95b3c57ddf7c811092672095563bd2e1336598b74c6d314b82e199f61bc02326bca563f45642167f5d40a2db0bc40b137bafb3e8c3318db8521997cb4ea591b3932db13ade1d50a94f1cb3b5ff8034cce2c8733b129d4973db6617ad450932e55d2bb6c81dd01cb36a3134c12cf4ba51c743f3a88eb955868c1f96823b6d1f0ccbc346b061fabcbb556f219ad58e612aaea475178df84a1a9b60c666981117291cc823e3f34a02f7af4fb3d31507f2a57c3d34391b05cdfcab02058ed95527d5dae930308dc5862934ba6811216f4cd68f7aac30ed8df0b180eda55dcd01848a03db4d71876e45397c5395391f708c2445549d26a169a72d9f295559861ad0be5526819650d26566ad6ca25dd0f54df0a81352006e75a5da3d92b4609f46c7a9f8fe01fe05eca4cde987e28f68fd9651de113ec87c4e6b03b52c907272a51d1f6a7be8c45cc097bf821267d258eb2378d32c95c4601cd000366c920a418e0de5890e79c9a628eeebe1208244f5d90d12cf8124f4424c8720299ce03045010bd0d618e7aa872e952abb987891befdc5ab70b7f82be30d4f64f6f93013a681ff8c09b5fab6218f4aa493627652c9ec7c6ba88291980b6e00e151201
Techniques (MITRE) (23)
-
Windows Service
-
Clear Windows Event Logs
-
Query Registry
-
Keylogging
-
Encrypted Channel
-
Boot or Logon Autostart Execution
-
Software Discovery
-
System Binary Proxy Execution
-
System Information Discovery
-
Process Discovery
-
Ingress Tool Transfer
-
File and Directory Discovery
-
Application Layer Protocol
-
Web Service
-
Process Injection
-
Deobfuscate/Decode Files or Information
-
Data Encoding
-
System Owner/User Discovery
-
Obfuscated Files or Information
-
Scheduled Task/Job
-
Modify Registry
-
Command and Scripting Interpreter
Malware (6)
-
FamilyPublished 26/02/2025 09:26 · Modified 26/02/2025 09:26
-
FamilyPublished 26/02/2025 09:26 · Modified 26/02/2025 09:26
-
FamilyPublished 19/02/2026 16:01 · Modified 19/02/2026 16:01
-
FamilyPublished 19/11/2025 08:54 · Modified 19/11/2025 08:54
-
FamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
-
FamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
Others (15)
- Hong Kong
- Singapore
- Taiwan
- China
- Thailand
- Japan
- Malaysia
- Philippines
- Information Technology
- Construction
- Healthcare
- Energy
- Telecommunications
- Government
- Manufacturing