PULSE NAME
MimiStick — imitators of Sticky Werewolf
WHITE MimiStick AlienVault 2024-09-27 Modified: 2024-10-27
25
IOCs
MEDIUM VOLUME
F.A.C.C.T. Threat Intelligence discovered a malicious file targeting Russian defense industry enterprises. Initially thought to be the work of Sticky Werewolf, further analysis revealed a new threat actor named MimiStick. The attack used a PDF lure mimicking a letter from the Russian Ministry of Labor. The malware employed a multi-stage infection chain, ultimately deploying a Sliver implant. Later findings confirmed the campaign was indeed Sticky Werewolf, who had expanded their toolkit to include Sliver implant alongside their existing Quasar RAT. The group registered multiple domains, including one impersonating the Ministry of Labor, likely for future phishing campaigns.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Sliver Quasar RAT
Indicators of Compromise (6 / 25 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 2849ad434d55b8f2bc067c37903b5ff5bad01dbd 2024-09-27
FileHash-SHA1 3100e869b1052dee920f7f2ca35da60abdf5aac0 2024-09-27
FileHash-SHA1 3fba74f0f7f91f665ad68db9004f1fec3486595b 2024-09-27
FileHash-SHA1 c15716d127961eb1ca4c4d6192af6e1c5c8a2d8d 2024-09-27
FileHash-SHA1 e8ba03b13f9b51abcc9a539d09f98b61b2b4ccd0 2024-09-27
FileHash-SHA1 efd81a26fd43124d435bc0223c5f42839f793d42 2024-09-27