Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
Security experts have identified a hacking group that targets companies in the materials research industry using a special toolkit that includes a customized remote access trojan (RAT) named Atharvan. Upon a compromise, attackers take a variety of actions. Clasiopa also utilized authorized software to sign with an outdated certification. The hacker used two backdoors for their attack, custom Atharvan and open-source Lilith RAT. After that, they utilize the compromised system to run PowerShell scripts, execute commands, and control processes. The hardcoded command and control (C2) address is contacted after the custom backdoor has been executed and before it establishes a mutex to prevent multiple instances of itself from running. The unique aspect is that it can be set up for scheduled communication with the C2 and can even be made to attempt connections on particular days of the week or at specific times. The researchers point out that some methods are used to protect Atharvan's contacts with the C2. Atharvan can download data from the infected machine run executables, execute commands, and exfiltrate the output.
Threat Profile:
| Tactic | Technique id | Technique |
| Resource Development | T1587 | Develop Capabilities |
| Execution | T1053 | Scheduled Task/Job |
| T1204 | User Execution | |
| T1059 | Command and Scripting Interpreter | |
| Defense Evasion | T1562 | Impair Defenses |
| T1070 | Indicator Removal | |
| T1055 | Process Injection | |
| T1562 | Impair Defenses | |
| Credential Access | T1110 | Brute Force |
| Discovery | T1016 | System Network Configuration Discovery |
| Command and Control | T1219 | Remote Access Software |
| Impact | T1489 | Service Stop |
| T1529 | System Shutdown/Reboot |
References:
The following reports contain further technical details:
[/emaillocker]