logo

APT15__2011__wp_dissecting-lurid-apt.pdf

ID: 51c71a59-fa17-4df3-841d-5939a91bdb66

STIX ID: report--51c71a59-fa17-4df3-841d-5939a91bdb66

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2011-09-23

Last Modified Date: 2011-09-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's report analyzes the "Lurid Downloader" (Enfal) targeted malware campaign that used spear-phishing PDFs (CVE-2009-4324) to compromise 1,465 hosts in 61 countries—primarily Russia and CIS—targeting government, diplomatic, research and space organizations; it details the malware's dropper/service behavior, command-and-control protocols and commands, C2 domains/IPs and MD5 indicators, campaign tracking (301 campaign codes), observed data-exfiltration activity, and provides cautious attribution context pointing to actors historically associated with Enfal.