talos · Crawled Sep 11, 2026
We've got one word for it, and it's usually the wrong one
15 IoCs 1 Malware
Read original article ↗
AI Summary
Cisco Talos identified a complex WebDAV-based infection chain used in an attack against a Ukrainian government organization. The campaign is attributed to the Russian threat actor UAT-10820 and delivers multiple payloads, including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager. The attackers abuse legitimate infrastructure such as the BNB Smart Chain for hosting and use fake CAPTCHA prompts to evade detection. The operation is assessed as opportunistic, focused on stealing cryptocurrency and credentials, with techniques including memory-resident malware, DLL sideloading via 'rundll32.exe', and use of vulnerable drivers to disable EDR solutions.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 15 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | Details → |
| MD5 | 2915b3f8b703eb744fc54c81f4a9c67f | Details → |
| Filename | VID001.exe | Details → |
| SHA-256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | Details → |
| MD5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | Details → |
| Filename | tmp00055df5.dll | Details → |
| SHA-256 | c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 | Details → |
| MD5 | 9a47c4d379998ade2f8f99e23a630c06 | Details → |
| Filename | sample.exe | Details → |
| SHA-256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | Details → |
| MD5 | 38de5b216c33833af710e88f7f64fc98 | Details → |
| Filename | SECOH-QAD.exe | Details → |
| SHA-256 | 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 | Details → |
| MD5 | f3e82419a43220a7a222fc01b7607adc | Details → |
| Filename | 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe | Details → |
MITRE ATT&CK TTPs 17 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1083 File and Directory Discovery · Discovery T1085 T1085 T1105 Ingress Tool Transfer · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1203 Exploitation for Client Execution · Execution T1204.001 Malicious Link · Execution T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1497.001 System Checks · Defense Evasion T1566 Phishing · Initial Access