Names | SLOWDRIFT | |
Category | Malware | |
Type | Reconnaissance, Backdoor, Info stealer, Downloader | |
Description | (FireEye) SLOWDRIFT is a launcher that communicates via cloud based infrastructure. It sends system information to the attacker command and control and then downloads and executes additional payloads. Lure documents distributing SLOWDRIFT were not tailored for specific victims, suggesting that TEMP.Reaper is attempting to widen its target base across multiple industries and in the private sector. SLOWDRIFT was seen being deployed against academic and strategic targets in South Korea using lure emails with documents leveraging the HWP exploit. Recent SLOWDRIFT samples were uncovered in June 2017 with lure documents pertaining to cyber crime prevention and news stories. These documents were last updated by the same actor who developed KARAE, POORAIM and ZUMKONG. | |
Information | <https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf> | |
MITRE ATT&CK | <https://attack.mitre.org/software/S0218/> |
Last change to this tool card: 23 April 2020
Download this tool card in JSON format
Previous: Sliver
Next: SLOWROLL
Changed | Name | Country | Observed | ||
APT groups | |||||
Reaper, APT 37, Ricochet Chollima, ScarCruft | 2012-Sep 2024 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |