talos · Crawled Sep 11, 2026

We've got one word for it, and it's usually the wrong one

15 IoCs 1 Malware
Read original article ↗

AI Summary

Cisco Talos identified a complex WebDAV-based infection chain used in an attack against a Ukrainian government organization. The campaign is attributed to the Russian threat actor UAT-10820 and delivers multiple payloads, including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager. The attackers abuse legitimate infrastructure such as the BNB Smart Chain for hosting and use fake CAPTCHA prompts to evade detection. The operation is assessed as opportunistic, focused on stealing cryptocurrency and credentials, with techniques including memory-resident malware, DLL sideloading via 'rundll32.exe', and use of vulnerable drivers to disable EDR solutions.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 15 extracted

Type Value Detail
SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 Details →
MD5 2915b3f8b703eb744fc54c81f4a9c67f Details →
Filename VID001.exe Details →
SHA-256 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 Details →
MD5 c2efb2dcacba6d3ccc175b6ce1b7ed0a Details →
Filename tmp00055df5.dll Details →
SHA-256 c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 Details →
MD5 9a47c4d379998ade2f8f99e23a630c06 Details →
Filename sample.exe Details →
SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f Details →
MD5 38de5b216c33833af710e88f7f64fc98 Details →
Filename SECOH-QAD.exe Details →
SHA-256 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 Details →
MD5 f3e82419a43220a7a222fc01b7607adc Details →
Filename 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe Details →

MITRE ATT&CK TTPs 17 techniques