Clasiopa: New Group Targets Materials Research

2023-02-23 Symantec

https://symantec-enterprise-blogs.security.com/threat-intelligence/clasiopa-materials-research

Thumbnail for Clasiopa: New Group Targets Materials Research

Symantec attributes intrusions against an Asian materials research organization to a previously unknown group it tracks as Clasiopa, while noting there is no firm evidence of the group’s origin or sponsor. The activity used a distinct toolset including the custom Atharvan RAT, modified Lilith RAT variants, Thumbsender for file-name collection and exfiltration, a custom proxy tool, and additional backdoors and hacktools. Observed tradecraft included possible brute-force access to public-facing servers, attempts to stop Symantec Endpoint Protection, clearing Sysmon and Windows event logs, and creating a scheduled task named "network service" to list files. Atharvan uses the mutex "SAPTARISHI-ATHARVAN-101", hardcoded HTTP POST communications with a Host header of "update.microsoft.com", scheduled C2 check-ins, and a hardcoded C2 address hosted in AWS South Korea, giving defenders concrete behavioral and IOC leads without supporting confident attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8aa6612c95c7cef49709596da43a0f8… 2023-02-23 2024-07-25
HASH 38f0f2d658e09c57fc78698482f2f63… 2023-02-23 2024-07-25
HASH c94c42177d4f9385b02684777a05966… 2023-02-23 2023-02-23
HASH 5b74b2176b8914b0c4e6215baab9e96… 2023-02-23 2023-02-23
HASH 8023b2c1ad92e6c5fec308cfafae371… 2023-02-23 2023-02-23
HASH f93ddb2377e02b0673aac6d540a558f… 2023-02-23 2023-02-23
HASH 940ab006769745b19de5e927d344c4a… 2023-02-23 2023-02-23
HASH 1569074db4680a9da6687fb79d33160… 2023-02-23 2023-02-23
HASH 0550e1731a6aa2546683617bd333113… 2023-02-23 2023-02-23
HASH 3aae54592fe902be0ca1ab29afe5980… 2023-02-23 2023-02-23
HASH 95f76a95adcfdd91cb626278006c164… 2023-02-23 2023-02-23

Related Actors

Related Reports

« Back