Names | August Stealer | |
Category | Malware | |
Type | Info stealer, Credential stealer, Exfiltration | |
Description | (Proofpoint) During the month of November, Proofpoint observed multiple campaigns from TA530 - an actor we have noted for their highly personalized campaigns - targeting customer service and managerial staff at retailers. These campaigns utilized “fileless” loading of a relatively new malware called August through the use of Word macros and PowerShell. August contains stealing functionality targeting credentials and sensitive documents from the infected computer. | |
Information | <https://www.proofpoint.com/us/threat-insight/post/august-in-december-new-information-stealer-hits-the-scene> <https://hazmalware.blogspot.de/2016/12/analysis-of-august-stealer-malware.html> | |
Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/win.august_stealer> | |
AlienVault OTX | <https://otx.alienvault.com/browse/pulses?q=tag:august%20stealer> |
Last change to this tool card: 13 May 2020
Download this tool card in JSON format
Previous: AuditCred
Next: AUMLIB
Changed | Name | Country | Observed | ||
APT groups | |||||
TA530 | [Unknown] | 2016-Nov 2016 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |