PULSE NAME
“Hack-for-hire” DeathStalker Actor Uses New PowerPepper Implant
WHITE DeathStalker AlienVault 2020-12-03 Modified: 2020-12-03
30
IOCs
MEDIUM VOLUME
"While tracking DeathStalker’s Powersing-based activities in May 2020, we detected a previously unknown implant that leveraged DNS over HTTPS as a C2 channel, as well as parts of its delivery chain. We named this new malware “PowerPepper”. We first spotted a variant of PowerPepper in the wild in mid-July 2020, as dropped from a Word Document that had been submitted on a public multiscanner service. PowerPepper implant and associated delivery chain has been continuously developed and operated since."
Indicators of Compromise (1 / 30 total)
All email hostname FileHash-SHA256 FileHash-MD5 FileHash-SHA1 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 46afa83e0b43fdb9062dd3e5fb7805997c432dd96f09ddf81f2162781daaf834 SHA256 of 871d64d8330d956593545dfff069194e 2020-12-03