PULSE NAME
VTA - Hackers use Golang source code interpreter to evade detection
WHITE DragonSpark Superpro 2023-01-24 Modified: 2023-02-23
22
IOCs
MEDIUM VOLUME
A Chinese-speaking hacking group tracked as ‘DragonSpark’ was observed employing Golang source code interpretation to evade detection while launching espionage attacks against organizations in East Asia. The threat actor, DragonSpark relies on an open-source tool called SparkRAT to steal sensitive data from compromised systems, execute commands, perform lateral network movement, and more.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Zegost Cobalt Strike Meterpreter Golang
Indicators of Compromise (5 / 22 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 14ebbed449ccedac3610618b5265ff803243313d 2023-01-24
FileHash-SHA1 2578efc12941ff481172dd4603b536a3bd322691 2023-01-24
FileHash-SHA1 6920f726d74efb7836a03d3acfc0f23af196765e 2023-01-24
FileHash-SHA1 83130d95220bc2ede8645ea1ca4ce9afc4593196 2023-01-24
FileHash-SHA1 bdf792c8250191bd2f5c167c8dbea5f7a63fa3b4 2023-01-24