ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Home > List all groups > List all tools > List all groups using tool SierraAlfa

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: SierraAlfa

TypeWorm, Loader
Description(Novetta) A self-install service-based executable, SierraAlfa begins a chain of infection that ultimately leads to the potential devastation of an entire network of computers. SierraAlfa is responsible for the distribution and activation of WhiskeyAlfa on a victim’s network. The observed samples of SierraAlfa were clearly built specifically for the SPE attacks as they contain infrastructure and account information specific to SPE’s networks.

Two variants have been observed: SierraAlfa-One and SierraAlfa-Two. SierraAlfa-One is the base model, while SierraAlfa-Two provides additional features to ensure the propagation of the malicious payload within.

Last change to this tool card: 20 April 2020

Download this tool card in JSON format

All groups using tool SierraAlfa


APT groups

XLazarus Group, Hidden Cobra, Labyrinth ChollimaNorth Korea2007-Jun 2022 HOTX

1 group listed (1 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]