PULSE NAME
Operation RestyLink: Targeted attack campaign targeting Japanese companies
WHITE DarkHotel AlienVault 2022-05-11 Modified: 2022-06-10
7
IOCs
LOW VOLUME
Since mid- April 2022 , multiple organizations have been observing targeted attack campaigns targeting Japanese companies. This attack campaign is believed to have been active in March 2022 , and it is possible that a related attack was also underway in October 2021 . For this reason, it is possible that attacks will continue in the future, rather than short-term, one-off attack campaigns.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Cobalt Strike - S0154
Indicators of Compromise (7)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain mbusabc.com 2022-05-11
domain youmiuri.com 2022-05-11
domain differentfor.com 2022-05-11
domain disknxt.com 2022-05-11
domain officehoster.com 2022-05-11
domain spffusa.org 2022-05-11
domain sseekk.xyz 2022-05-11