ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Report
Search
Home > List all groups > List all tools > List all groups using tool BLUELIGHT

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: BLUELIGHT

NamesBLUELIGHT
CategoryMalware
TypeReconnaissance, Backdoor, Info stealer, Credential stealer, Downloader, Exfiltration
Description(Volexity) The BLUELIGHT malware family uses different cloud providers to facilitate C2. This specific sample leveraged the Microsoft Graph API for its C2 operations. Upon start-up, BLUELIGHT performs an oauth2 token authentication using hard-coded parameters. Once the client is authenticated, BLUELIGHT creates a new subdirectory in the OneDrive appfolder and populates it with several subdirectories used by the C2 protocol.
Information<https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/>
MITRE ATT&CK<https://attack.mitre.org/software/S0657/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.bluelight>

Last change to this tool card: 13 October 2023

Download this tool card in JSON format

All groups using tool BLUELIGHT

ChangedNameCountryObserved

APT groups

 Reaper, APT 37, Ricochet Chollima, ScarCruftNorth Korea2012-Dec 2023X

1 group listed (1 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]