Clasiopa: New Group Targets Materials Research
2023-02-23 • Symantec •
https://symantec-enterprise-blogs.security.com/threat-intelligence/clasiopa-materials-research
Symantec attributes intrusions against an Asian materials research organization to a previously unknown group it tracks as Clasiopa, while noting there is no firm evidence of the group’s origin or sponsor. The activity used a distinct toolset including the custom Atharvan RAT, modified Lilith RAT variants, Thumbsender for file-name collection and exfiltration, a custom proxy tool, and additional backdoors and hacktools. Observed tradecraft included possible brute-force access to public-facing servers, attempts to stop Symantec Endpoint Protection, clearing Sysmon and Windows event logs, and creating a scheduled task named "network service" to list files. Atharvan uses the mutex "SAPTARISHI-ATHARVAN-101", hardcoded HTTP POST communications with a Host header of "update.microsoft.com", scheduled C2 check-ins, and a hardcoded C2 address hosted in AWS South Korea, giving defenders concrete behavioral and IOC leads without supporting confident attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8aa6612c95c7cef49709596da43a0f8… | 2023-02-23 | 2024-07-25 |
| HASH | 38f0f2d658e09c57fc78698482f2f63… | 2023-02-23 | 2024-07-25 |
| HASH | c94c42177d4f9385b02684777a05966… | 2023-02-23 | 2023-02-23 |
| HASH | 5b74b2176b8914b0c4e6215baab9e96… | 2023-02-23 | 2023-02-23 |
| HASH | 8023b2c1ad92e6c5fec308cfafae371… | 2023-02-23 | 2023-02-23 |
| HASH | f93ddb2377e02b0673aac6d540a558f… | 2023-02-23 | 2023-02-23 |
| HASH | 940ab006769745b19de5e927d344c4a… | 2023-02-23 | 2023-02-23 |
| HASH | 1569074db4680a9da6687fb79d33160… | 2023-02-23 | 2023-02-23 |
| HASH | 0550e1731a6aa2546683617bd333113… | 2023-02-23 | 2023-02-23 |
| HASH | 3aae54592fe902be0ca1ab29afe5980… | 2023-02-23 | 2023-02-23 |
| HASH | 95f76a95adcfdd91cb626278006c164… | 2023-02-23 | 2023-02-23 |