PULSE NAME
Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain
WHITE eric.ford 2022-12-19 Modified: 2022-12-19
82
IOCs
HIGH VOLUME
Nozomi reports that the Glupteba malware botnet has sprung back into action, infecting devices worldwide after its operation was disrupted by Google almost a year ago. Nozomi analysis reveals a new, large-scale Glupteba campaign that started in June 2022 and is still ongoing based on data from blockchain transactions, TLS certificate registrations and reverse engineering Glupteba samples.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Glupteba
Indicators of Compromise (1 / 82 total)
All BitcoinAddress FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 e2aad08f11d13fcb4fcd6ddedcb716e9 MD5 of c6d4ce67dd25764f571a84caa19fa6c2b067cae6 2022-12-19