PULSE NAME
Unknown actor leverages miners, Iron ransomware and Cobalt Strike
WHITE bartblaze 2018-05-05 Modified: 2018-05-05
0
IOCs
LOW VOLUME
Unknown actor, possibly Chinese, uses PowerShell and shell scripts to infect machines with Iron ransomware, coinminers, and may also achieve persistent access with Cobalt Strike. There's a Linux variant for the cryptominer as well, and they may move laterally.
Indicators of Compromise (0)
All
No indicators.