WildCard__2024__WildCard_The_APT_Behind_SysJoker_Targets_Critical_Sectors_in_Israel.pdf
ID: ce5e487e-b42c-4b4a-b233-19fbfaba86a3
STIX ID: report--ce5e487e-b42c-4b4a-b233-19fbfaba86a3
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2024-01-16
Last Modified Date: 2024-01-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report identifies a new APT group named WildCard, initially detected with the SysJoker malware targeting Israel’s educational sector in 2021, and traces its evolution through increasingly sophisticated variants (DMAdevice, AppMessagingRegistrar, RustDown) that masquerade as legitimate software and leverage OneDrive as dead drops and a Rust-based backdoor for multi-platform targeting, with C2 infrastructure and links to Operation ElectricPowder, signaling sustained, high-skill campaigns against Israeli critical sectors and complex, multi-stage intrusion capabilities.
