PULSE NAME
menuPass Returns with New Malware and New Attacks
WHITE Stone Panda AlienVault 2017-02-21 Modified: 2017-06-14
71
IOCs
HIGH VOLUME
In 2016, from September through November, an APT campaign known as “menuPass” targeted Japanese academics working in several areas of science, along with Japanese pharmaceutical and a US-based subsidiary of a Japanese manufacturing organizations. In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group, they also used a new Trojan called “ChChes” by the Japan Computer Emergency Response Team Coordination Center (JPCERT). In contrast to PlugX and PIVY, which are used by multiple campaigns, ChChes appears to be unique to this group. An analysis of the malware family can be found later in this blog.
Indicators of Compromise (1 / 71 total)
All FileHash-SHA256 hostname FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 009b639441ad5c1260f55afde2d5d21fc5b4f96c 2017-02-21