PULSE NAME
A Dive into Latest Campaign
WHITE APT41 AlienVault 2024-08-09 Modified: 2024-09-08
51
IOCs
HIGH VOLUME
Earth Baku, an advanced persistent threat actor, has broadened its operations from the Indo-Pacific region to Europe, the Middle East, and Africa, targeting countries like Italy, Germany, UAE, and Qatar. The group leverages public-facing applications like IIS servers as entry points, deploying sophisticated malware toolsets such as the Godzilla webshell, StealthVector, StealthReacher, and SneakCross. StealthVector and StealthReacher are customized loaders that stealthily launch backdoor components, while SneakCross is a modular backdoor utilizing Google services for command-and-control activities. During post-exploitation, Earth Baku employs tools like a customized iox tool, Rakshasa, and Tailscale for persistence, along with MEGAcmd for data exfiltration.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Godzilla StealthVector StealthReacher SneakCross Cobalt Strike - S0154 Rakshasa Tailscale MEGAcmd
Indicators of Compromise (12 / 51 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 28072e4a3bc3376aba096045824f4c34 2024-08-09
FileHash-MD5 4141c4b827ff67c180096ff5f2cc1474 2024-08-09
FileHash-MD5 72070b165d1f11bd4d009a81bf28a3e5 2024-08-09
FileHash-MD5 bc85062de0f70afd44bb072b0b71a8cc 2024-08-09
FileHash-MD5 bcac2cbda36019776d7861f12d9b59c4 2024-08-09
FileHash-MD5 c33247bc3e7e8cb72133e47930e6ddad 2024-08-09
FileHash-MD5 d72f202c1d684c9a19f075290a60920f 2024-08-09
FileHash-MD5 e9625ce47b87085b66e0ee6e17ecb333 2024-08-09
FileHash-MD5 ee7faba27a2c5f7acb5b06e94aa318e0 2024-08-09
FileHash-MD5 f062183da590aba5e911d2392bc29181 2024-08-09
FileHash-MD5 f0953ed4a679b987a2da955788737602 2024-08-09
FileHash-MD5 f42867e74bbc41767bffacc0de7bfa5e 2024-08-09