PULSE NAME
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion .
WHITE PetrP.73 2025-09-30 Modified: 2025-10-30
73
IOCs
HIGH VOLUME
In May 2024, an intrusion attributed to the Lunar Spider threat actor commenced when a user executed a malicious JavaScript file disguised as a tax form. This file, associated with the Lunar Spider group, contained obfuscated code that triggered the download of an MSI installer, which subsequently deployed a Brute Ratel DLL file using the Windows utility rundll32. Upon execution, the Brute Ratel loader injected Latrodectus malware into the explorer.exe process, establishing command and control (C2) communications with multiple domains. The attack began with extensive reconnaissance activities approximately one hour after the initial access, utilizing built-in Windows commands to enumerate hosts and domains. Subsequent actions included establishing a BackConnect session for remote access via VNC, and accessing an unattend.xml file to extract plaintext domain administrator credentials.
Indicators of Compromise (10 / 73 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 100e03eb4e9dcdab6e06b2b26f800d47a21d338885f5dc1b42c56a32429c9168 2025-09-30
FileHash-SHA256 1a8ebf914ebea34402eecbf0985f05ae413663708d2fcc842fc27057ac5ec4ed 2025-09-30
FileHash-SHA256 203eda879dbdb128259cd658b22c9c21c66cbcfa1e2f39879c73b4dafb84c592 2025-09-30
FileHash-SHA256 36bc32becf287402bf0e9c918de22d886a74c501a33aa08dcb9be2f222fa6e24 SHA256 of 33a6b39fbe8ec45afab14af88fd6fa8e96885bf1 2025-09-30
FileHash-SHA256 37471af00673af4080ee21bd248536147e450d2eff45e8701a95d1163a9d62fe SHA256 of 5348970723b378c7cae35bb03d8736f8e5a9f0ac 2025-09-30
FileHash-SHA256 411dfb067a984a244ff0c41887d4a09fbbcd8d562550f5d32d58a6a6256bd7b2 2025-09-30
FileHash-SHA256 6c3b2490e99cd8397fb79d84a5638c1a0c4edb516a4b0047aa70b5811483db8f 2025-09-30
FileHash-SHA256 77eede38abdc740f000596e374b6842902653aeafb6c63011388ebb22ec13e28 2025-09-30
FileHash-SHA256 8fb5034aedf41f8c8c4c4022fdde7db3c70a5a7c7b5b4dec7f6a57715c18a5bf 2025-09-30
FileHash-SHA256 f4cb6b684ea097f867d406a978b3422bbf2ecfea39236bf3ab99340996b825de SHA256 of 4a013f752c2bf84ca37e418175e0d9b6f61f636d 2025-09-30