FIN7__2017__Operation_Grand_Mars.pdf
ID: 2cde410d-6091-4a3f-b9ee-76ea36577bf5
STIX ID: report--2cde410d-6091-4a3f-b9ee-76ea36577bf5
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2017-01-18
Last Modified Date: 2017-01-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Trustwave SpiderLabs report analyzes "Operation Grand Mars," a financially motivated, organized campaign that used spear-phishing Word macros to deploy multi-stage VBS/JS/PowerShell loaders and memory-resident payloads (Anunak/Carbanak, Cobalt Strike, reverse shells). Attackers used cloud services (Google Docs/Forms, Pastebin) for C2 and victim tracking, obtained code-signing certificates to evade detection, performed lateral movement (pass-the-hash), and exfiltrated data; the report provides technical analysis, IOCs (hashes, domains, IPs), and remediation guidance.
