RADIO_PANDA__2017__appendix-following-the-trail-of-blacktechs-cyber-espionage-campaigns.pdf
ID: 8158441c-08e9-4d2b-8ed7-6b7dbebe28ee
STIX ID: report--8158441c-08e9-4d2b-8ed7-6b7dbebe28ee
Threat Score
82/100
Uploaded: 2026-08-19
Published Date: 2017-06-21
Last Modified Date: 2017-06-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's technical analysis of the BlackTech / Shrouded Crossbow espionage campaign describes multiple malware families (PLEAD, DRIGO, Waterbear, BIFROST variants including KIVARS and XBOW), their delivery (spear-phishing, cloud-hosted payloads, router compromise, exploited IIS/CVE and a Hacking Team exploit for fileless execution), C2 protocols, capabilities (remote commands, Google Drive/Gmail-based exfiltration, in-memory loaders), and provides extensive IoCs (SHA256 hashes, C2 domains and IPs) to support detection and response.
