PULSE NAME
Greedy Sponge Targets Mexico with AllaKore RAT and SystemBC
WHITE Greedy Sponge AlienVault 2025-08-21 Modified: 2025-08-21
139
IOCs
HIGH VOLUME
A financially motivated threat group dubbed Greedy Sponge has been targeting Mexican organizations since 2021 with a modified version of AllaKore RAT and SystemBC malware. The group uses spear-phishing and drive-by downloads to deliver custom packaged installers containing the RAT. Recent updates include improved geofencing, more potent secondary infections, and enhanced credential stealing capabilities. The AllaKore payload has been heavily modified to enable theft of banking credentials and authentication information. The group has shown consistent development of their tactics and techniques over time, demonstrating persistence and some level of operational success. Despite their longevity, they are not considered highly advanced, focusing primarily on financial fraud against Mexican entities across various industries.
Indicators of Compromise (34 / 139 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 058bde7b3385b70d59120b24390377af 2025-08-21
FileHash-MD5 09096930751d28d388d3e0de003bcb7b 2025-08-21
FileHash-MD5 12dbbfccd463ec884f788abd5933f8aa 2025-08-21
FileHash-MD5 29a9d202ba2d46047edba9539abba0cd 2025-08-21
FileHash-MD5 2f0b96c3262108012dcf9a940ae461da 2025-08-21
FileHash-MD5 30f6cb0f6d417cd2cb9756dc5d05d4cd 2025-08-21
FileHash-MD5 35932f5856dbf8ba51e048b3b2bb2d7b 2025-08-21
FileHash-MD5 40291ec2bd7f23aa76435d5d14f96758 2025-08-21
FileHash-MD5 42300099a726353abfddbfdd5773de83 2025-08-21
FileHash-MD5 47ead282cd7c6a667d9b4cc9b0c6935e 2025-08-21
FileHash-MD5 59401f25ac88f1c1fe0a5981dc29ea57 2025-08-21
FileHash-MD5 59c6ae6bbe3d048d267d4900c9585828 2025-08-21
FileHash-MD5 733f33faedb263d914163043b5242f0a 2025-08-21
FileHash-MD5 746c9f8f002fb8569d19cb2cdc1295ed 2025-08-21
FileHash-MD5 750a33531763724e8db051750a08cf99 2025-08-21
FileHash-MD5 768a78b4b12efe721139c474fbf139f4 2025-08-21
FileHash-MD5 81444a9c9f74be2c8ba32542bcc68bab 2025-08-21
FileHash-MD5 a3d03ec08345e7cf02818122fc5b31f3 2025-08-21
FileHash-MD5 a50d0d1bf9ab8291e986e59ebd92be14 2025-08-21
FileHash-MD5 aa8b32b21dcf44a332f9c9d13af3cd7d 2025-08-21
FileHash-MD5 ac2fa680544b1b1e452753b78b460a59 2025-08-21
FileHash-MD5 ac69851a5144e0eb28923ca2e3b8cbe2 2025-08-21
FileHash-MD5 b2cb036f919d3cd003023c95c4bbb983 2025-08-21
FileHash-MD5 b4c5d6749222539ff6fb6c83174867ea 2025-08-21
FileHash-MD5 b90a102fccedad57b06dc8fb6a58895b 2025-08-21
FileHash-MD5 bd3782580c0ddbda2288b2d5d5a72258 2025-08-21
FileHash-MD5 bd9d9a4be3d93acf3228607b435a4828 2025-08-21
FileHash-MD5 c48f0372aecf3a7c3d8fab599e7afcde 2025-08-21
FileHash-MD5 c74e97cf0086782ab8d22919b11f9c9d 2025-08-21
FileHash-MD5 cddc9f377fc5a70ee8140f763aa52f98 2025-08-21
FileHash-MD5 d355ff7b4e022eff5c2b5a5aabae5ad0 2025-08-21
FileHash-MD5 df9b2ff8bd9164ae0f2c802c555d2c4f 2025-08-21
FileHash-MD5 e641690408faf6320fd7c820644ec889 2025-08-21
FileHash-MD5 e78fa70b0e38c7c8c29048cebba2dd74 2025-08-21