TA505__2019__SectorJ04_Group_s_Increased_Activity_in_2019.pdf
ID: d2ac661c-7bf1-4e50-9e80-7b049e299e74
STIX ID: report--d2ac661c-7bf1-4e50-9e80-7b049e299e74
Threat Score
82/100
Uploaded: 2026-08-19
Published Date: 2019-08-29
Last Modified Date: 2019-08-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SectorJ04's 2019 activity is analyzed, focusing on its shift from targeted operations to broader distribution across Europe, North America, and Asia, the deployment of multiple backdoor families (ServHelper, FlawedAmmy RAT, RMS RAT, AdroMut, FlowerPippi), and changes in infection chains (MSI, NSIS, SFX) with spear phishing. The report documents evolving spam methods, digital signatures used to authenticate malware, IoCs, and MITRE ATT&CK mappings, highlighting ongoing, sophisticated campaigns by a Russian-based cybercrime group targeting sectors from finance to healthcare.
