logo

Cybergun_Technical_Analysis_of_the_Armageddons_Infostealer.pdf

ID: 4a937e15-79d9-4118-afdf-e347d8747e83

STIX ID: report--4a937e15-79d9-4118-afdf-e347d8747e83

Threat Score

72/100

Uploaded: 2026-08-11

Published Date: 2023-03-19

Last Modified Date: 2023-03-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a technical analysis of the Armageddon Group's Infostealer: a C++ Windows PE compiled in 2022 that uses phishing-delivered RTF/LNK/DOCX to run scripts (PowerShell/PE/VBScript), achieves persistence via a RUN registry entry and mutex (Global\flashUpdated_r), enumerates and collects numerous file types, stores filenames locally (IconsCache.db, profiles_c.ini, trend.txt), and exfiltrates data over HTTPS to dynamically generated subdomains of celticso.ru; the report includes a YARA rule, a SHA-256 sample hash, a C2 domain IOC, and MITRE ATT&CK mappings.