PULSE NAME
StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved?
WHITE StrongPity AlienVault 2017-12-08 Modified: 2019-07-12
19
IOCs
MEDIUM VOLUME
Continuing our research into FinFisher – the infamous spyware known also as FinSpy and sold to governments and their agencies worldwide – we noticed that the FinFisher malware in our previously-documented campaign, which had strong indicators of internet service provider (ISP) involvement, had been replaced by different spyware. Detected by ESET as Win32/StrongPity2, this spyware notably resembles one that was attributed to the group called StrongPity. As well as detecting and blocking this threat, all ESET products – including the free ESET Online scanner – thoroughly clean systems compromised by StrongPity2.
Indicators of Compromise (1 / 19 total)
All FileHash-SHA256 domain URL hostname FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 462e85023952d23b74d697911653604b40497424e7a6fe505366addae6c375f7 2017-12-08