PULSE NAME
Dalbit (m00nlight): Chinese Hacker Group APT Attack Campaign
WHITE Dalbit AlienVault 2023-02-15 Modified: 2023-02-15
211
IOCs
HIGH VOLUME
Researchers identified the Dalbit (m00nlight) hacking group that has been targeting Korean companies since 2022 and is known as the “Dalbit” (Moonlight).
Indicators of Compromise (3 / 211 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname aa.zxcss.com 2023-02-15
hostname fk.m00nlight.top 2023-02-15
hostname sk1.m00nlight.top 2023-02-15