MirageFox
Description
MirageFox is a remote access tool used against Windows systems. It appears to be an upgraded version of a tool known as Mirage, which is a RAT believed to originate in 2012.
(SecureWorks) Mirage phones home to its C2 servers using a standard HTTP request. From the activity CTU researchers have observed when executing Mirage in a malware sandbox, this communication commonly occurs over ports 80, 443 and 8080, and it can implement SSL for added security.
Names
Name |
---|
MirageFox |
Category
Malware
Type
- Backdoor
- Info stealer
Information
- https://www.secureworks.com/research/the-mirage-campaign
- https://www.intezer.com/miragefox-apt15-resurfaces-with-new-tools-based-on-old-ones/
Mitre Attack
Malpedia
Alienvault Otx
Other Information
Uuid
850be0f0-e2cf-4c68-a739-6691ec513e99
Last Card Change
2020-05-14