216.73.216.6

Unveiling the Past and Present of APT-K-47 Weapon: Asyncshell

· Published 26/11/2024 21:42 · Modified 26/11/2024 22:04

Export JSON

Essential information

Published
26/11/2024 21:42
Modified
26/11/2024 22:04
Tags
2024-11-26 asyncshell base64 c2 chm hajj
Related entities
3 observables, 1 intrusion sets (apt), 8 techniques (mitre), 3 malware, 2 others

Description

The intelligence report details the discovery and analysis of an attack campaign by the APT-K-47 organization, also known as Mysterious Elephant. The attackers used a file to execute a malicious payload, which is an upgraded version of their tool. The new version, dubbed -v4, features variant algorithm for string hiding, disguised requests, and reduced log messages. The report traces the evolution of through four versions, from its first discovery in January 2024 to the latest capture. The tool has been used in attacks targeting various countries, including Pakistan, Bangladesh, and Turkey, often using decoy documents related to government and religious topics.

External references