Over the course of three months, Volexity observed UTA0388 using various themes and fictional identities across dozens of spear phishing campaigns. As time passed, Volexity observed UTA0388 broaden their targeting and send emails in a variety of different languages, including English, Chinese, Japanese, French, and German. In most cases, the initial email sent by UTA0388 contained a link to phishing content hosted on a cloud-based service that would lead to malware. Author: AlienVault
Related Tags:
govershell c2
randomdir8char
llms
govershell
UTA0388
websocket
rar
zip
persistence
Associated Indicators:
53AF82811514992241E232E5C04E5258E506F9BC2361B5A5B718B4E4B5690040
0414217624404930137EC8F6A26AEBD8A3605FE089DBFB9F5AAAA37A9E2BAD2E
88782D26F05D82ACD084861D6A4B9397D5738E951C722EC5AFED8D0F6B07F95E
4C041C7C0D5216422D5D22164F83762BE1E70F39FB8A791D758A816CDF3779A9
2FFE1E4F4DF34E1ACA3B8A8E93EEE34BFC4B7876CEDD1A0B6CA5D63D89A26301
A5EE55A78D420DBBA6DEC0B87FFD7AD6252628FD4130ED4B1531EDE960706D2D
998E314A8BABF6DB11145687BE18DC3B8652A3DD4B36C115778B7CA5F240AAE4
7D7D75E4D524E32FC471EF2D36FD6F7972C05674A9F2BAC909A07DFD3E19DD18
AD5718F6810714BC6527CC86D71D34D8C556FE48706D18B5D14F0261EB27D942


