← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion .
In May 2024, an intrusion attributed to the Lunar Spider threat actor commenced when a user executed a malicious JavaScript file disguised as a tax form. This file, associated with the Lunar Spider group, contained obfuscated code that triggered the download of an MSI installer, which subsequently deployed a Brute Ratel DLL file using the Windows utility rundll32. Upon execution, the Brute Ratel loader injected Latrodectus malware into the explorer.exe process, establishing command and control (C2) communications with multiple domains.
The attack began with extensive reconnaissance activities approximately one hour after the initial access, utilizing built-in Windows commands to enumerate hosts and domains. Subsequent actions included establishing a BackConnect session for remote access via VNC, and accessing an unattend.xml file to extract plaintext domain administrator credentials.
MITRE ATT&CK & Malware Families
Indicators of Compromise (10 / 73 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 495363b0262b62dfc38d7bfb7b5541aa | — | 2025-09-30 | |
| FileHash-MD5 | 4b3e9c9e018659d1cf04daf82abe3b64 | — | 2025-09-30 | |
| FileHash-MD5 | 50abc42faa70062e20cd5e2a2e2b6633 | — | 2025-09-30 | |
| FileHash-MD5 | 91889658f1c8e1462f06f019b842f109 | MD5 of 33a6b39fbe8ec45afab14af88fd6fa8e96885bf1 | 2025-09-30 | |
| FileHash-MD5 | 9eaa8464110883a15115b68ffa1ecf7d | MD5 of 5348970723b378c7cae35bb03d8736f8e5a9f0ac | 2025-09-30 | |
| FileHash-MD5 | a2b6479a69b51ae555f695b243e4fda1 | — | 2025-09-30 | |
| FileHash-MD5 | ad3c52316e0059c66bc1dd680cf9edad | — | 2025-09-30 | |
| FileHash-MD5 | c8ea31665553cbca19b22863eea6ca2c | — | 2025-09-30 | |
| FileHash-MD5 | ccb6d3cb020f56758622911ddd2f1fcb | MD5 of 4a013f752c2bf84ca37e418175e0d9b6f61f636d | 2025-09-30 | |
| FileHash-MD5 | d7bd590b6c660716277383aa23cb0aa9 | — | 2025-09-30 |