PULSE NAME
Attack Activity Analysis Using SSH+TOR Tunnels for Covert Persistence
WHITE APT-C-13 AlienVault 2026-04-28 Modified: 2026-04-29
38
IOCs
MEDIUM VOLUME
APT-C-13 (Sandworm), also known as FROZENBARENTS, is a state-sponsored advanced persistent threat group conducting global cyber espionage targeting government agencies, diplomatic departments, energy enterprises, and research organizations. Recently detected samples reveal the group's use of nested SSH and TOR tunnel architecture to establish covert communication channels. The attack begins with spear-phishing emails delivering malicious LNK files disguised as PDF documents. Upon execution, the payload deploys TOR hidden services mapping internal ports (SMB/445, RDP/3389) to onion domains, while SSH services with public key authentication provide encrypted remote access. The malware employs obfs4 protocol to obfuscate TOR traffic, evading deep packet inspection. Persistence is achieved through scheduled tasks masquerading as legitimate applications like Opera GX and Dropbox, establishing an anonymous shadow management infrastructure for sustained intelligence collection.
Indicators of Compromise (12 / 38 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 09f402a02b615dcd14786aaa840db0a2 2026-04-28
FileHash-MD5 0b6f7356919b9632c1158681ee0462f3 2026-04-28
FileHash-MD5 1b39fce74193dd2cd5c36b2f8b626273 2026-04-28
FileHash-MD5 2156c270ffe8e4b23b67efed191b9737 2026-04-28
FileHash-MD5 227b3fa386cad73f0f388d801060e2c8 2026-04-28
FileHash-MD5 487557c9b7288a6b035911a7652ad57c 2026-04-28
FileHash-MD5 4d5074d6e0722ceec45a083fa8444164 2026-04-28
FileHash-MD5 53ac08488544ad1fefd6363db44549cf 2026-04-28
FileHash-MD5 5db8e71b8e82661408f96b43e7ae8faf 2026-04-28
FileHash-MD5 6616717dfb2a795113b47d862c5412e2 2026-04-28
FileHash-MD5 99732e49668e56527963742922277459 2026-04-28
FileHash-MD5 a6d095dc0e01f97db7e74cb5bed402dc 2026-04-28