PULSE NAME
Unfurling Hemlock: Threat group uses cluster bomb campaigns
WHITE Unfurling Hemlock AlienVault 2024-07-01 Modified: 2024-07-31
41
IOCs
MEDIUM VOLUME
A threat actor dubbed Unfurling Hemlock has been observed distributing hundreds of thousands of malware samples in a campaign lasting several months. The malware is distributed using a 'cluster bomb' technique where each sample contains multiple stages of nested executable files, each containing additional malware payloads. The distributed malware includes stealers like Redline, RisePro, and Mystic Stealer, as well as loaders like Amadey and SmokeLoader. The campaign appears financially motivated and targets victims globally with no specific industry focus. The actor is suspected to be Eastern European based on language artifacts and hosting infrastructure.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Redline Mystic Stealer RisePro Amadey - S1025 SmokeLoader
Indicators of Compromise (3 / 41 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 14031a40973ef9851a9e6dd2d1843b00247c32f0 2024-07-01
FileHash-SHA1 e04fea9ed997d9ad2d73dd8ca661625d7292eb98 2024-07-01
FileHash-SHA1 05a6cb77200d23c45296b4af0d88006adf9b77be 2024-07-01