PULSE NAME
Leaked source code for Ammyy Admin turned into FlawedAmmyy RAT
WHITE TA505 AlienVault 2018-03-12 Modified: 2019-04-03
38
IOCs
MEDIUM VOLUME
Proofpoint researchers have discovered a previously undocumented remote access Trojan (RAT) called FlawedAmmyy that has been used since the beginning of 2016 in both highly targeted email attacks as well as massive, multi-million message campaigns. Narrow attacks targeted the Automotive industry among others, while the large malicious spam campaigns appear to be associated with threat actor TA505, an actor responsible for many large-scale attacks since at least 2014.
Indicators of Compromise (3 / 38 total)
All FileHash-SHA256 URL FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 8364f1e42b4467f527e875e4cf20fe8a 2019-04-03
FileHash-MD5 57f59b1e113dffb36015af3523344ab1 2019-04-03
FileHash-MD5 d46778cf23d9b6d092be5f75b86700bb 2019-04-03