Snake Keylogger in Geopolitical Affairs: Abuse of Trusted Java Utilities in Cybercrime Operations

The S2 Group’s intelligence team has identified through adversary tracking a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET, targeting various types of victims, such as companies, governments or individuals. The campaign has been identified as using spearphishing emails offering oil products. Author: AlienVault

Related Tags:
Logistic

Petroleum

Snake Keylogger

T1588.002

T1566.001

spearphishing

maas

T1555

T1574.002

Associated Indicators:
D44BAE3E448D78CDB976B7F811BE53F32EFB28D0D2BA964D09EDD79A95DCC4B3

0171212441AEF19491692062218AAA6FBA9684F59E162691AB056A7369569AD9

E31EDA04B9EE78BB41C990ECA89554FFADAB27A5C47D5EFD66F11F5947958DDE

D3CA4ED0A462C73C55D3AED4CFA5A969EACFDDE152F67437FE3BB14FEFB17612

9DAE36CF2664E4BD348B1C7BCD9E886243FDD86E04D854E9A49E80CE358AA868

7DAF0AA227D0E846EDD1229CD744E3AFD8CA3898E12836605D8F08038EF34203

CCDE5A1AE465A65B483F8F97E3D4B97957FC869CC4ACA8B4FDD02A821AAF45A8

B33D93E82B4A964C1306D40B054E6A2703E050357A513AB8873651DD4D669F4B

0877F1E39454438733DF34BFEC11FC23023A449C6ECE07F0D15A852D140E64C5