Microsoft Word - MSUpdater Trojan Whitepaper [MG4].docx
ID: 76faf3e1-9e0d-41b8-ae32-fa92c5b2055e
STIX ID: report--76faf3e1-9e0d-41b8-ae32-fa92c5b2055e
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2012-01-31
Last Modified Date: 2012-01-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Zscaler/Seculert report analyzes the "MSUpdater" RAT used in targeted phishing campaigns (malicious PDF attachments, including exploitation of CVE-2010-2883) against aerospace/defense and energy-related organizations; it documents VM-aware dropper behavior, detailed C2 beaconing patterns (/search..., /microsoftupdate/..., upload/download endpoints), WHOIS/domain correlations, and a consolidated list of MD5 IoCs to support detection and remediation.
