Cryptcat
Description
(FireEye) Four files tested in 2014 are based on the open-source project, cryptcat. Analysis of these cryptcat binaries indicates that the actor continually modified them to decrease AV detection rates. One of these files was deployed in a TEMP.Veles target’s network. The compiled version with the least detections was later re-tested in 2017 and deployed less than a week later during TEMP.Veles activities in the target environment.
Names
Name |
---|
Cryptcat |
Category
Tools
Type
- Tunneling
Information
- https://www.fireeye.com/blog/threat-research/2018/10/triton-attribution-russian-government-owned-lab-most-likely-built-tools.html
- http://cryptcat.sourceforge.net/
Other Information
Uuid
8321ac32-dc29-4d0e-a9dd-c626178fb3ee
Last Card Change
2020-04-20