PULSE NAME
Wild Neutron – Economic espionage threat actor returns
WHITE AlienVault 2015-07-09 Modified: 2017-08-23
56
IOCs
HIGH VOLUME
A powerful threat actor known as “Wild Neutron” (also known as “Jripbot” and “Morpho“) has been active since at least 2011, infecting high profile companies for several years by using a combination of exploits, watering holes and multi-platform malware. The latest round of attacks in 2015 uses a stolen code signing certificate belonging to Taiwanese electronics maker Acer and an unknown Flash Player exploit. Wild Neutron hit the spotlight in 2013, when it successfully infected companies such as Apple, Facebook, Twitter and Microsoft. This attack took advantage of a Java zero-day exploit and used hacked forums as watering holes. The 2013 incident was highly publicized and, in the aftermath, the threat actor went dark for almost one year.
Indicators of Compromise (11 / 56 total)
All domain hostname FileHash-MD5 CVE Mutex YARA FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 ee24a7ad8d137e54b854095188de0bbf 2017-08-23
FileHash-MD5 088472f712d1491783bbad87bcc17c48 2017-08-23
FileHash-MD5 1582d68144de2808b518934f0a02bfd6 2017-08-23
FileHash-MD5 95ffe4ab4b158602917dd2a999a8caf8 2017-08-23
FileHash-MD5 dee8297785b70f490cc00c0763e31b69 2017-08-23
FileHash-MD5 48319e9166cda8f605f9dce36f115bc8 2017-08-23
FileHash-MD5 f0fff29391e7c2e7b13eb4a806276a84 2017-08-23
FileHash-MD5 342887a7ec6b9f709adcb81fef0d30a3 2017-08-23
FileHash-MD5 14ba21a3a0081ef60e676fd4945a8bdc 2017-08-23
FileHash-MD5 1f5f5db7b15fe672e8db091d9a291df0 2017-08-23
FileHash-MD5 0fa3657af06a8cc8ef14c445acd92c0f 2017-08-23