PULSE NAME
Breaking The Weakest Link Of The Strongest Chain
WHITE Kasper AlienVault 2017-02-16 Modified: 2017-06-14
12
IOCs
MEDIUM VOLUME
Around July last year, more than a 100 Israeli servicemen were hit by a cunning threat actor. The attack compromised their devices and exfiltrated data to the attackers’ command and control server. In addition, the compromised devices were pushed Trojan updates, which allowed the attackers to extend their capabilities. The operation remains active at the time of writing this post, with attacks reported as recently as February 2017. The campaign, which experts believe is still in its early stages, targets Android OS devices. Once the device is compromised, a process of sophisticated intelligence gathering starts, exploiting the ability to access the phone’s video and audio capabilities, SMS functions, and location.
Indicators of Compromise (12)
All domain FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
domain goodydaddy.com 2017-02-16
domain androidbak.com 2017-02-16
domain endpointup.com 2017-02-16
domain siteanalysto.com 2017-02-16
domain droidback.com 2017-02-16
FileHash-SHA1 b8237782486a26d5397b75eeea7354a777bff63a 2017-02-16
FileHash-SHA1 782a0e5208c3d9e8942b928857a24183655e7470 2017-02-16
FileHash-SHA1 10f27d243adb082ce0f842c7a4a3784b01f7248e 2017-02-16
FileHash-SHA1 9b923303f580c999f0fdc25cad600dd3550fe4e0 2017-02-16
FileHash-SHA1 5f71a8a50964dae688404ce8b3fbd83d6e36e5cd 2017-02-16
FileHash-SHA1 09c3af7b0a6957d5c7c80f67ab3b9cd8bef88813 2017-02-16
FileHash-SHA1 0a5dc47b06de545d8236d70efee801ca573115e7 2017-02-16