APT15__2011__wp_dissecting-lurid-apt.pdf
ID: 51c71a59-fa17-4df3-841d-5939a91bdb66
STIX ID: report--51c71a59-fa17-4df3-841d-5939a91bdb66
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2011-09-23
Last Modified Date: 2011-09-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's report analyzes the "Lurid Downloader" (Enfal) targeted malware campaign that used spear-phishing PDFs (CVE-2009-4324) to compromise 1,465 hosts in 61 countries—primarily Russia and CIS—targeting government, diplomatic, research and space organizations; it details the malware's dropper/service behavior, command-and-control protocols and commands, C2 domains/IPs and MD5 indicators, campaign tracking (301 campaign codes), observed data-exfiltration activity, and provides cautious attribution context pointing to actors historically associated with Enfal.
