New Indicators of Compromise for APT Group Nitro Uncovered - Palo Alto Networks BlogPalo Alto Networks Blog
ID: 3fc6b858-3b63-4739-969a-dd4c4d18d61e
STIX ID: report--3fc6b858-3b63-4739-969a-dd4c4d18d61e
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2014-10-07
Last Modified Date: 2014-10-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes mid‑2014 activity by the APT group “Nitro” that deployed multiple malware families (Spindest, PCClient, Farfli) through compromised legitimate websites and spear-phishing campaigns; analysts identified numerous IOCs (SHA256/MD5 hashes, filenames, C2 domains and IPs) across several targeted organizations and linked samples by shared C2 infrastructure and DNS/IP resolution overlap.
