Cryptcat

Description

(FireEye) Four files tested in 2014 are based on the open-source project, cryptcat. Analysis of these cryptcat binaries indicates that the actor continually modified them to decrease AV detection rates. One of these files was deployed in a TEMP.Veles target’s network. The compiled version with the least detections was later re-tested in 2017 and deployed less than a week later during TEMP.Veles activities in the target environment.

Names

Name
Cryptcat

Category

Tools

Type

  • Tunneling

Information

Other Information

Uuid

8321ac32-dc29-4d0e-a9dd-c626178fb3ee

Last Card Change

2020-04-20