PULSE NAME
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion .
WHITE PetrP.73 2025-09-30 Modified: 2025-10-30
73
IOCs
HIGH VOLUME
In May 2024, an intrusion attributed to the Lunar Spider threat actor commenced when a user executed a malicious JavaScript file disguised as a tax form. This file, associated with the Lunar Spider group, contained obfuscated code that triggered the download of an MSI installer, which subsequently deployed a Brute Ratel DLL file using the Windows utility rundll32. Upon execution, the Brute Ratel loader injected Latrodectus malware into the explorer.exe process, establishing command and control (C2) communications with multiple domains. The attack began with extensive reconnaissance activities approximately one hour after the initial access, utilizing built-in Windows commands to enumerate hosts and domains. Subsequent actions included establishing a BackConnect session for remote access via VNC, and accessing an unattend.xml file to extract plaintext domain administrator credentials.
Indicators of Compromise (10 / 73 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 495363b0262b62dfc38d7bfb7b5541aa 2025-09-30
FileHash-MD5 4b3e9c9e018659d1cf04daf82abe3b64 2025-09-30
FileHash-MD5 50abc42faa70062e20cd5e2a2e2b6633 2025-09-30
FileHash-MD5 91889658f1c8e1462f06f019b842f109 MD5 of 33a6b39fbe8ec45afab14af88fd6fa8e96885bf1 2025-09-30
FileHash-MD5 9eaa8464110883a15115b68ffa1ecf7d MD5 of 5348970723b378c7cae35bb03d8736f8e5a9f0ac 2025-09-30
FileHash-MD5 a2b6479a69b51ae555f695b243e4fda1 2025-09-30
FileHash-MD5 ad3c52316e0059c66bc1dd680cf9edad 2025-09-30
FileHash-MD5 c8ea31665553cbca19b22863eea6ca2c 2025-09-30
FileHash-MD5 ccb6d3cb020f56758622911ddd2f1fcb MD5 of 4a013f752c2bf84ca37e418175e0d9b6f61f636d 2025-09-30
FileHash-MD5 d7bd590b6c660716277383aa23cb0aa9 2025-09-30