Andariel deploys DTrack and Maui ransomware

2022-08-09 Kaspersky

https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/

Thumbnail for Andariel deploys DTrack and Maui ransomware

Kaspersky linked a 2021 Maui ransomware incident to Andariel, also known as Silent Chollima or Stonefly, with low to medium confidence based on DTrack deployment, 3proxy use, and overlap with prior activity. In the Japanese victim environment, the actor deployed a DTrack variant about ten hours before Maui ransomware, collecting host data such as network configuration, process lists, netstat output, interface information, ping results, and browser history. Maui was run from a Windows temporary path with arguments setting eight threads, self-deletion behavior, and encryption of the E: drive, while key files were written under the same temporary directory. Additional DTrack infections in India, Vietnam, and Russia and exploitation of vulnerable HFS and WebLogic services suggest opportunistic global targeting of financially viable organizations rather than a single sector focus.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cf236bf5b41d26967b1ce04ebbdb4041 2022-08-09 2023-02-10
HASH 739812e2ae1327a94e441719b885bd19 2022-08-09 2023-02-09
HASH 92adc5ea29491d9245876ba0b295739… 2022-08-09 2023-02-09
HASH ad4eababfe125110299e5a24be84472e 2022-08-09 2023-02-09
HASH f2f787868a3064407d79173ac5fc0864 2022-08-09 2023-02-09
HASH 6122c94cbfa11311bea7129ecd5aea6… 2022-08-09 2023-02-09
HASH 60425a4d5ee04c8ae09bfe28ca33bf9… 2022-08-09 2023-02-09
HASH a557a0c67b5baa7cf64bd4d42103d3b… 2022-08-09 2023-02-09
HASH 94db86c214f4ab401e84ad26bb0c9c2… 2022-08-09 2022-08-09
HASH 87e3fc08c01841999a8ad8fe25f12fe4 2022-08-09 2022-08-09
HASH 102a6954a16e80de814bee7ae2b893f… 2022-08-09 2022-08-09
HASH 2f553cba839ca4dab201d3f8154bae2a 2022-08-09 2022-08-09
HASH feb79a5a2bdf0bcf0777ee51782dc50… 2022-08-09 2022-08-09
HASH 95247511a611ba3d8581c7c6b8b1a38a 2022-08-09 2022-08-09
HASH 1c4aa2cbe83546892c98508cad9da59… 2022-08-09 2022-08-09
HASH 5bc4b606f4c0f8cd2e6787ae049bf5bb 2022-08-09 2022-08-09
IPv4 145.232.235.222 2020-12-18 2022-08-09

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back