Malware
GHOSTBLADE
According to Google, GHOSTBLADE is delivered via the DarkSword exploit chain. GHOSTBLADE is a dataminer written in JavaScript that collects and exfiltrates a wide variety of data from a compromised device. Data collected by GHOSTBLADE is exfiltrated to an attacker-controlled server over HTTP(S). Unlike GHOSTKNIFE and GHOSTSABER, GHOSTBLADE is less capable and does not support any additional modules or backdoor-like functionality; it also does not operate continuously. However, similar to GHOSTKNIFE, GHOSTBLADE also contains code to delete crash reports, but targets a different directory where they may be stored.
Indicators of Compromise 14
Domain t[.]me/YATA0000 IP 103[.]106[.]190[.]217 IP 103[.]226[.]155[.]200 IP 103[.]226[.]155[.]201 IP 103[.]238[.]129[.]112 IP 103[.]97[.]128[.]67 IP 107[.]175[.]49[.]181 IP 151[.]243[.]126[.]191 IP 162[.]4[.]136[.]30 IP 202[.]8[.]120[.]249 IP 223[.]26[.]63[.]56 IP 38[.]181[.]52[.]95 IP 38[.]22[.]89[.]117 IP 93[.]152[.]221[.]37