logo

The Mirage Campaign

ID: f2a2b486-1a36-400b-9c9a-9c1a531b2d20

STIX ID: report--f2a2b486-1a36-400b-9c9a-9c1a531b2d20

Threat Score

75/100

Uploaded: 2026-08-07

Published Date: 2013-09-26

Last Modified Date: 2013-09-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dell SecureWorks CTU analysed the Mirage (MirageFox) RAT campaign (since April 2012) that targeted executives at energy, oil and military organizations via spearphishing droppers that masquerade as PDFs; the report documents two main Mirage variants (POST and GET with custom encodings/Base64), persistence and C2 behaviors (HTTP/SSL over ports 80/443/8080, use of HTran and dDNS), custom environment-specific builds, sinkholed infrastructure, victim counts and geographic distribution, and provides IOCs including MD5 hashes and Yara rules for detection.