s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.steelhook

📛 Threat Title

Malware family: STEELHOOK

Category: STEELHOOK First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.steelhook`. Printable name: STEELHOOK.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.steelhook

IOC database

Type
domain
Value
ps1.steelhook
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.steelhook

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The MASEPIE tool facilitated the deployment of OPENSSH for tunneling, STEELHOOK PowerShell scripts to extract data from Chrome/Edge browsers, and the OCEANMAP backdoor. Within an hour of the initial compromise, additional tools like IMPACKET and SMBEXEC were created for network reconnaissance and horizontal movement attempts.

  • web:apt.etda.or.th

    Threat Group Cards: A Threat Actor Encyclopedia Tool: STEELHOOK ... Last change to this tool card: 27 December 2024 Download this tool card in JSON format All groups using tool STEELHOOK ... 1 group listed (1 APT, 0 other, 0 unknown) ↑

  • web:dailysecurityreview.com

    According to CERT-UA#8399 alert, the malware's primary role is to download additional malware on the infected device and steal data. The Ukrainian CERT-UA also notes that APT28 used a collection of PowerShell scripts called 'STEELHOOK' to carry out data theft from web browsers based on Chrome.

  • web:infoaday.com

    Dec 29, 2023 NewsroomE-mail Safety / Malware The Laptop Emergency Response Group of Ukraine (CERT-UA) has warned of a brand new phishing marketing campaign orchestrated by the Russia-linked APT28 group to deploy beforehand undocumented malware akin to OCEANMAP, MASEPIE, and STEELHOOK to reap delicate data. The exercise, which was detected by the company between December 15 […]

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the STEELHOOK malware family including references, samples and yara signatures.

  • web:sos-vo.org

    The campaign involves previously undocumented malware such as OCEANMAP, MASEPIE, and STEELHOOK . The agency discovered the activity between December 15 and December 25, 2023, targeting government entities with email messages urging recipients to click on a link to view a document.

  • web:vulners.com

    CERT-UA warns of new malware campaign targeting Ukrainian and Polish organizations. Malware includes OCEANMAP, MASEPIE, and STEELHOOK , used by APT28 group to harvest sensitive data.

  • web:www.bleepingcomputer.com

    The latest news about Steelhook Russian military hackers target Ukraine with new MASEPIE malware Ukraine's Computer Emergency Response Team (CERT) is warning of a new phishing campaign that ...

  • web:www.hivepro.com

    Attack: A recent phishing campaign attributed to the Russia-linked APT28 group has been identified targeting Ukrainian government entities and Polish organizations with email messages urging recipients to click on a link to view a document. The goal is to deploy previously undocumented malware , including OCEANMAP, MASEPIE, and STEELHOOK , to gather sensitive information.

  • web:www.ibm.com

    The flowchart below outlines the stages of an infection via the search-ms protocol, custom WebDAV servers and the delivery of first and second-stage malware : MASEPIE, OCEANMAP and STEELHOOK respectively. Fig. 1: Example infection chain of recent ITG05 campaign

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.