timb-machine / timb-machine/linux-malware
[Intel]: https://www.crowdstrike.com/blog/an-analysis-of-lightbasin-telecommunications-attacks
@timb-machine is already working on this.
Since Apr 19, 2022.
- Dominant language
- HTML
- Stars
- 1.2k
- Forks
- 95
- PR merge metrics
- No merged PRs in 30d
Description
Area
Malware reports
Parent threat
Credential Access, Defense Evasion, Discovery, Lateral Movement, Collection, Command and Control, Impact
Finding
https://www.crowdstrike.com/blog/an-analysis-of-lightbasin-telecommunications-attacks
Industry reference
vertical:Telecomms
attack:T1573.001:Symmetric Cryptography
attack:T1590:Gather Victim Network Information
attack:T1562.004:Disable or Modify System Firewall
attack:T1048.001:Exfiltration Over Unencrypted Non-C2 Protocol
attack:T1021.004:SSH
attack:T1037.004:RC Scripts
attack:T1090.001:Internal Proxy
attack:T1090.002:External Proxy
attack:T1110.003:Password Spraying
uses:RedirectionToNull
uses:Non-persistentStorage
Malware reference
https://github.com/timb-machine/linux-malware/issues/134
SLAPSTICK
STEELCORGI
PingPong
TINYSHELL
CordScan
SIGTRANslator
Fast Reverse Proxy
Microsocks Proxy
ProxyChains
Actor reference
LIMINAL PANDA
LightBasin
UNC1945
Component
Solaris, Linux, Telecomms
Scenario
Internal specialist services
Scenario variation
Enclave deployment
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.