The Mirage Campaign
ID: f2a2b486-1a36-400b-9c9a-9c1a531b2d20
STIX ID: report--f2a2b486-1a36-400b-9c9a-9c1a531b2d20
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2013-09-26
Last Modified Date: 2013-09-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dell SecureWorks CTU analysed the Mirage (MirageFox) RAT campaign (since April 2012) that targeted executives at energy, oil and military organizations via spearphishing droppers that masquerade as PDFs; the report documents two main Mirage variants (POST and GET with custom encodings/Base64), persistence and C2 behaviors (HTTP/SSL over ports 80/443/8080, use of HTran and dDNS), custom environment-specific builds, sinkholed infrastructure, victim counts and geographic distribution, and provides IOCs including MD5 hashes and Yara rules for detection.
