Charming_Kitten__2019__Twas_the_night_before.pdf
ID: 0ccfd976-10fb-46cc-a6bb-3f48bf67d074
STIX ID: report--0ccfd976-10fb-46cc-a6bb-3f48bf67d074
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-07-05
Last Modified Date: 2019-07-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NewsBeef (reported as NewsBeef/APT33) ran a 2016–2017 campaign targeting Saudi Arabian government and related organizations using spearphishing (malicious macro-enabled Office documents), watering-hole JavaScript injections that fingerprint and redirect victims, and poisoned installers that launch PowerShell downloaders, PowerSploit reflective injection, and an in-memory Pupy backdoor communicating to obfs3-protected C2 servers; the report includes technical analysis and many IOCs (MD5s, domains, IPs, URLs).
