ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Report
Search
Home > List all groups > List all tools > List all groups using tool Graphiron

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Graphiron

NamesGraphiron
CategoryMalware
TypeReconnaissance, Backdoor, Info stealer, Credential stealer
Description(Symantec) Graphiron is a two-stage threat consisting of a downloader (Downloader.Graphiron) and a payload (Infostealer.Graphiron).

The payload is capable of carrying out the following tasks:

• Reads MachineGuid
• Obtains the IP address from https://checkip.amazonaws.com
• Retrieves the hostname, system info, and user info
• Steals data from Firefox and Thunderbird
• Steals private keys from MobaXTerm.
• Steals SSH known hosts
• Steals data from PuTTY
• Steals stored passwords
• Takes screenshots
• Creates a directory
• Lists a directory
• Runs a shell command
• Steals an arbitrary file
Information<https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/nodaria-ukraine-infostealer>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.graphiron>

Last change to this tool card: 22 June 2023

Download this tool card in JSON format

All groups using tool Graphiron

ChangedNameCountryObserved

APT groups

 SaintBear, Lorec53Russia2021-Oct 2022 

1 group listed (1 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]