PULSE NAME
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion .
WHITE PetrP.73 2025-09-30 Modified: 2025-10-30
73
IOCs
HIGH VOLUME
In May 2024, an intrusion attributed to the Lunar Spider threat actor commenced when a user executed a malicious JavaScript file disguised as a tax form. This file, associated with the Lunar Spider group, contained obfuscated code that triggered the download of an MSI installer, which subsequently deployed a Brute Ratel DLL file using the Windows utility rundll32. Upon execution, the Brute Ratel loader injected Latrodectus malware into the explorer.exe process, establishing command and control (C2) communications with multiple domains. The attack began with extensive reconnaissance activities approximately one hour after the initial access, utilizing built-in Windows commands to enumerate hosts and domains. Subsequent actions included establishing a BackConnect session for remote access via VNC, and accessing an unattend.xml file to extract plaintext domain administrator credentials.
Indicators of Compromise (10 / 73 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 23fff588e3e5cc6678e1f77fab9318d60f3ac55f 2025-09-30
FileHash-SHA1 2d92890374904b49d3c54314d02b952e1a714e99 2025-09-30
FileHash-SHA1 333e1c5967a9a6c881c9573a3222bed6ada911c6 2025-09-30
FileHash-SHA1 33a6b39fbe8ec45afab14af88fd6fa8e96885bf1 2025-09-30
FileHash-SHA1 38999890b3a2c743e0abea1122649082a5fa1281 2025-09-30
FileHash-SHA1 4a013f752c2bf84ca37e418175e0d9b6f61f636d 2025-09-30
FileHash-SHA1 5348970723b378c7cae35bb03d8736f8e5a9f0ac 2025-09-30
FileHash-SHA1 8dfa63c0bb611e18c8331ed5b89decf433ac394a 2025-09-30
FileHash-SHA1 97d72c8bbcf367be6bd5e80021e3bd3232ac309a 2025-09-30
FileHash-SHA1 ba99cd73b74c64d6b1257b7db99814d1dc7d76b1 2025-09-30