PULSE NAME
xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
WHITE OilRig AlienVault 2019-09-23 Modified: 2019-09-23
27
IOCs
MEDIUM VOLUME
Between May and June 2019, Unit 42 observed previously unknown tools used in the targeting of transportation and shipping organizations based in Kuwait. The first known attack in this campaign targeted a Kuwait transportation and shipping company in which the actors installed a backdoor tool named Hisoka. Several custom tools were later downloaded to the system in order to carry out post-exploitation activities. All of these tools appear to have been created by the same developer. We were able to collect several variations of these tools including one dating back to July 2018.
Indicators of Compromise (1 / 27 total)
All domain FileHash-SHA256 hostname email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4 2019-09-23