logo

Attor__2019__ESET_discovers_Attor_a_spy_platform_with_curious_GSM_fingerprinting_WeLiveSecurity.pdf

ID: f9313b23-6342-4c66-98ba-e0ffe16b357f

STIX ID: report--f9313b23-6342-4c66-98ba-e0ffe16b357f

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2019-10-11

Last Modified Date: 2019-10-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET discovered Attor, a highly targeted, modular espionage platform active since ~2013 that infects Windows hosts via a dispatcher-and-plugin architecture to collect sensitive data (screenshots, audio, keystrokes, file/device metadata). Notable capabilities include GSM device fingerprinting via AT commands, strong hybrid encryption for plugins/logs, Tor-based C2 (onion FTP with hardcoded credentials) and persistence/evasion techniques (process injection, scheduled tasks, service installation), with operations focused on Russian-speaking and Eastern European diplomatic/government targets.