

Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
July 19, 2022
Rewterz Threat Alert – NJRAT – Active IOCs
July 19, 2022
Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
July 19, 2022
Rewterz Threat Alert – NJRAT – Active IOCs
July 19, 2022Severity
High
Analysis Summary
APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 03e63cd919347693a86a53c70671a92c
- ad283d7b7b3c73f4b55ce50273b63c0e
SHA-256
- f83e760744db95babf1e630a857c6aaa4f4908f4c0f489a334e40a91ac3be4eb
- c2e053d2eadcbfe327f2dbe737208a75730bad0dbcab49bfa019c4428de2fdca
SHA-1
- 6ae9c1fafc9556c6c1d11a96faaad2591ad359e6
- 0deaad54340fa38e89611230629df0f43e21687b
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment