logo

New Indicators of Compromise for APT Group Nitro Uncovered - Palo Alto Networks BlogPalo Alto Networks Blog

ID: 3fc6b858-3b63-4739-969a-dd4c4d18d61e

STIX ID: report--3fc6b858-3b63-4739-969a-dd4c4d18d61e

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2014-10-07

Last Modified Date: 2014-10-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes mid‑2014 activity by the APT group “Nitro” that deployed multiple malware families (Spindest, PCClient, Farfli) through compromised legitimate websites and spear-phishing campaigns; analysts identified numerous IOCs (SHA256/MD5 hashes, filenames, C2 domains and IPs) across several targeted organizations and linked samples by shared C2 infrastructure and DNS/IP resolution overlap.