PULSE NAME
MimiStick — imitators of Sticky Werewolf
WHITE MimiStick AlienVault 2024-09-27 Modified: 2024-10-27
25
IOCs
MEDIUM VOLUME
F.A.C.C.T. Threat Intelligence discovered a malicious file targeting Russian defense industry enterprises. Initially thought to be the work of Sticky Werewolf, further analysis revealed a new threat actor named MimiStick. The attack used a PDF lure mimicking a letter from the Russian Ministry of Labor. The malware employed a multi-stage infection chain, ultimately deploying a Sliver implant. Later findings confirmed the campaign was indeed Sticky Werewolf, who had expanded their toolkit to include Sliver implant alongside their existing Quasar RAT. The group registered multiple domains, including one impersonating the Ministry of Labor, likely for future phishing campaigns.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Sliver Quasar RAT
Indicators of Compromise (25)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0756de02dd3b4be840d31c8871148f7f 2024-09-27
FileHash-MD5 5ed144351c41eb690d86c523690eb265 2024-09-27
FileHash-MD5 67aa63c4518a3604e37f89ad0d39a34d 2024-09-27
FileHash-MD5 725e5068bd68c3d055f3a814f402a8be 2024-09-27
FileHash-MD5 7e151444c98ef2cf084eed8e6d4be807 2024-09-27
FileHash-MD5 873454911a81a6c892838c44cbb3059b 2024-09-27
FileHash-SHA1 2849ad434d55b8f2bc067c37903b5ff5bad01dbd 2024-09-27
FileHash-SHA1 3100e869b1052dee920f7f2ca35da60abdf5aac0 2024-09-27
FileHash-SHA1 3fba74f0f7f91f665ad68db9004f1fec3486595b 2024-09-27
FileHash-SHA1 c15716d127961eb1ca4c4d6192af6e1c5c8a2d8d 2024-09-27
FileHash-SHA1 e8ba03b13f9b51abcc9a539d09f98b61b2b4ccd0 2024-09-27
FileHash-SHA1 efd81a26fd43124d435bc0223c5f42839f793d42 2024-09-27
FileHash-SHA256 3877f9fd6b21ee735130421dcf997cf000ae66b20a1c6a490f23431b2f95fa90 2024-09-27
FileHash-SHA256 5ad093aa3eaf2bb76003f8f2f9de9b1368640aa320fa8d77df2c773f75186a71 2024-09-27
FileHash-SHA256 65096aa2895025d94b934eb4198ea160e067e8e5c97d9ea252cb2de3870b7b2f 2024-09-27
FileHash-SHA256 8d83a598aa61a3f2e61bfdcdfc7b29b4c8d357eb43562d349053defa1ce50d78 2024-09-27
FileHash-SHA256 b262dd5373213c5af573a08b409f8142c7f9f92b19536d7d78b4515d23452321 2024-09-27
FileHash-SHA256 ff16334c4cbbfed4bfca23436493397d0465c643cce6cbe41426067bb1ce14ff 2024-09-27
domain about-tech.ru 2024-09-27
domain borosan.ru 2024-09-27
domain min-trud-gov.ru 2024-09-27
domain mysafer.ru 2024-09-27
domain orkprank.ru 2024-09-27
domain rtxcore.ru 2024-09-27
domain techitzone.ru 2024-09-27