logo

Charming_Kitten__2019__Twas_the_night_before.pdf

ID: 0ccfd976-10fb-46cc-a6bb-3f48bf67d074

STIX ID: report--0ccfd976-10fb-46cc-a6bb-3f48bf67d074

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-07-05

Last Modified Date: 2019-07-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NewsBeef (reported as NewsBeef/APT33) ran a 2016–2017 campaign targeting Saudi Arabian government and related organizations using spearphishing (malicious macro-enabled Office documents), watering-hole JavaScript injections that fingerprint and redirect victims, and poisoned installers that launch PowerShell downloaders, PowerSploit reflective injection, and an in-memory Pupy backdoor communicating to obfs3-protected C2 servers; the report includes technical analysis and many IOCs (MD5s, domains, IPs, URLs).