TF-MAL-ps1.steelhook
📛 Threat Title
Malware family: STEELHOOK
Description
ThreatFox malware family `ps1.steelhook`. Printable name: STEELHOOK.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.steelhook
IOC database
- Type
- domain
- Value
ps1.steelhook- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.steelhook
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The MASEPIE tool facilitated the deployment of OPENSSH for tunneling, STEELHOOK PowerShell scripts to extract data from Chrome/Edge browsers, and the OCEANMAP backdoor. Within an hour of the initial compromise, additional tools like IMPACKET and SMBEXEC were created for network reconnaissance and horizontal movement attempts.
-
web:apt.etda.or.th
Threat Group Cards: A Threat Actor Encyclopedia Tool: STEELHOOK ... Last change to this tool card: 27 December 2024 Download this tool card in JSON format All groups using tool STEELHOOK ... 1 group listed (1 APT, 0 other, 0 unknown) ↑
-
web:dailysecurityreview.com
According to CERT-UA#8399 alert, the malware's primary role is to download additional malware on the infected device and steal data. The Ukrainian CERT-UA also notes that APT28 used a collection of PowerShell scripts called 'STEELHOOK' to carry out data theft from web browsers based on Chrome.
-
web:infoaday.com
Dec 29, 2023 NewsroomE-mail Safety / Malware The Laptop Emergency Response Group of Ukraine (CERT-UA) has warned of a brand new phishing marketing campaign orchestrated by the Russia-linked APT28 group to deploy beforehand undocumented malware akin to OCEANMAP, MASEPIE, and STEELHOOK to reap delicate data. The exercise, which was detected by the company between December 15 […]
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the STEELHOOK malware family including references, samples and yara signatures.
-
web:sos-vo.org
The campaign involves previously undocumented malware such as OCEANMAP, MASEPIE, and STEELHOOK . The agency discovered the activity between December 15 and December 25, 2023, targeting government entities with email messages urging recipients to click on a link to view a document.
-
web:vulners.com
CERT-UA warns of new malware campaign targeting Ukrainian and Polish organizations. Malware includes OCEANMAP, MASEPIE, and STEELHOOK , used by APT28 group to harvest sensitive data.
-
web:www.bleepingcomputer.com
The latest news about Steelhook Russian military hackers target Ukraine with new MASEPIE malware Ukraine's Computer Emergency Response Team (CERT) is warning of a new phishing campaign that ...
-
web:www.hivepro.com
Attack: A recent phishing campaign attributed to the Russia-linked APT28 group has been identified targeting Ukrainian government entities and Polish organizations with email messages urging recipients to click on a link to view a document. The goal is to deploy previously undocumented malware , including OCEANMAP, MASEPIE, and STEELHOOK , to gather sensitive information.
-
web:www.ibm.com
The flowchart below outlines the stages of an infection via the search-ms protocol, custom WebDAV servers and the delivery of first and second-stage malware : MASEPIE, OCEANMAP and STEELHOOK respectively. Fig. 1: Example infection chain of recent ITG05 campaign
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.