PULSE NAME
Sofacys Komplex OS X Trojan
WHITE Sofacy AlienVault 2016-09-26 Modified: 2017-08-30
10
IOCs
LOW VOLUME
Unit 42 researchers identified a new OS X Trojan associated with the Sofacy group that we are now tracking with the ‘Komplex’ tag using the Palo Alto Networks AutoFocus threat intelligence platform. The Sofacy group, also known as APT28, Pawn Storm, Fancy Bear, and Sednit, continues to add to the variety of tools they use in attacks; in this case, targeting individuals in the aerospace industry running the OS X operating system. During our analysis, we determined that Komplex was used in a previous attack campaign targeting individuals running OS X that exploited a vulnerability in the MacKeeper antivirus application to deliver Komplex as a payload. Komplex shares a significant amount of functionality and traits with another tool used by Sofacy – the Carberp variant that Sofacy had used in previous attack campaigns on systems running Windows.
Indicators of Compromise (6 / 10 total)
All FileHash-SHA256 domain IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 45a93e4b9ae5bece0d53a3a9a83186b8975953344d4dfb340e9de0015a247c54 2016-09-26
FileHash-SHA256 cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4 2016-09-26
FileHash-SHA256 2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134 2016-09-26
FileHash-SHA256 227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5 2016-09-26
FileHash-SHA256 96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3 2016-09-26
FileHash-SHA256 c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7 2016-09-26