logo

TA505__2019__SectorJ04_Group_s_Increased_Activity_in_2019.pdf

ID: d2ac661c-7bf1-4e50-9e80-7b049e299e74

STIX ID: report--d2ac661c-7bf1-4e50-9e80-7b049e299e74

Threat Score

82/100

Uploaded: 2026-08-19

Published Date: 2019-08-29

Last Modified Date: 2019-08-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SectorJ04's 2019 activity is analyzed, focusing on its shift from targeted operations to broader distribution across Europe, North America, and Asia, the deployment of multiple backdoor families (ServHelper, FlawedAmmy RAT, RMS RAT, AdroMut, FlowerPippi), and changes in infection chains (MSI, NSIS, SFX) with spear phishing. The report documents evolving spam methods, digital signatures used to authenticate malware, IoCs, and MITRE ATT&CK mappings, highlighting ongoing, sophisticated campaigns by a Russian-based cybercrime group targeting sectors from finance to healthcare.