Please enable JavaScript.
Coggle requires JavaScript to display documents.
APT 41 (Malware used (Crosswalk.bin, Lowkey, Binload, lowpurr, Sadflower,…
APT 41
Malware used
Crosswalk.bin
Lowkey
Binload, lowpurr
Sadflower, frontman
Jaypotato
What is it?
Ransomware/spyware as primary tool
Group of hackers
Main goals are to spy and steal info or get financial gains
Stats
45 malware
46 hijacked mails
Telecom targeting
System specific targeti g
DPAPI
Decrypted payload
Volume Serial ID
Deadeye dropper
Supply chain compromise
Trojanizing legitimate software
LOL (2014)
FIFA
Trojanized with SOGU
Teamviewer (2017)
Trojanizing tools
POISONPLUG.SHADOW
SOGU
CRACKSHOT
Messagetap
Stilling info from messaging apps and SMS
Lostlink
Compromised game developer