logo

WildCard__2024__WildCard_The_APT_Behind_SysJoker_Targets_Critical_Sectors_in_Israel.pdf

ID: ce5e487e-b42c-4b4a-b233-19fbfaba86a3

STIX ID: report--ce5e487e-b42c-4b4a-b233-19fbfaba86a3

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2024-01-16

Last Modified Date: 2024-01-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report identifies a new APT group named WildCard, initially detected with the SysJoker malware targeting Israel’s educational sector in 2021, and traces its evolution through increasingly sophisticated variants (DMAdevice, AppMessagingRegistrar, RustDown) that masquerade as legitimate software and leverage OneDrive as dead drops and a Rust-based backdoor for multi-platform targeting, with C2 infrastructure and links to Operation ElectricPowder, signaling sustained, high-skill campaigns against Israeli critical sectors and complex, multi-stage intrusion capabilities.