Attor__2019__ESET_discovers_Attor_a_spy_platform_with_curious_GSM_fingerprinting_WeLiveSecurity.pdf
ID: f9313b23-6342-4c66-98ba-e0ffe16b357f
STIX ID: report--f9313b23-6342-4c66-98ba-e0ffe16b357f
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2019-10-11
Last Modified Date: 2019-10-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET discovered Attor, a highly targeted, modular espionage platform active since ~2013 that infects Windows hosts via a dispatcher-and-plugin architecture to collect sensitive data (screenshots, audio, keystrokes, file/device metadata). Notable capabilities include GSM device fingerprinting via AT commands, strong hybrid encryption for plugins/logs, Tor-based C2 (onion FTP with hardcoded credentials) and persistence/evasion techniques (process injection, scheduled tasks, service installation), with operations focused on Russian-speaking and Eastern European diplomatic/government targets.
