ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Report
Search
Home > List all groups > List all tools > List all groups using tool NachoCheese

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: NachoCheese

NamesNachoCheese
NACHOCHEESE
Cyruslish
TWOPENCE
VIVACIOUSGIFT
CategoryMalware
TypeBackdoor, Tunneling
DescriptionAccording to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.
Information<https://blog.lexfo.fr/ressources/Lexfo-WhitePaper-The_Lazarus_Constellation.pdf>
<https://us-cert.cisa.gov/ncas/analysis-reports/ar20-239b>
<https://baesystemsai.blogspot.com/2017/02/lazarus-false-flag-malware.html>
<https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/apt/rpt-apt38-2018.pdf>
<https://www.welivesecurity.com/2017/02/16/demystifying-targeted-malware-used-polish-banks/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.nachocheese>

Last change to this tool card: 29 December 2022

Download this tool card in JSON format

Previous: N1stAgent
Next: Naid

All groups using tool NachoCheese

ChangedNameCountryObserved

APT groups

XLazarus Group, Hidden Cobra, Labyrinth ChollimaNorth Korea2007-Sep 2024 HOTX
     ↳ Subgroup: BeagleBoyzNorth Korea2014-Feb 2016 

2 groups listed (2 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]