Nightshade Panda, APT 9, Group 27

Description

(Softpedia) Arbor’s ASERT team is now reporting that, after looking deeper at that particular campaign, and by exposing a new trail in the group’s activities, they managed to identify a new RAT that was undetectable at that time by most antivirus vendors.

Named Trochilus, this new RAT was part of Group 27’s malware portfolio that included six other malware strains, all served together or in different combinations, based on the data that needed to be stolen from each victim.

This collection of malware, dubbed the Seven Pointed Dagger by ASERT experts, included two different PlugX versions, two different Trochilus RAT versions, one version of the 3012 variant of the 9002 RAT, one EvilGrab RAT version, and one unknown piece of malware, which the team has not entirely decloaked just yet.

Names

NameName-Giver
Nightshade PandaCrowdStrike
APT 9Mandiant
Group 27ASERT
FlowerLadyContext
FlowerShowContext

Country

Motivation

  • Information theft and espionage

First Seen

2013

Observed Sectors

Observed Countries

Tools

Operations

Other Information

Uuid

8a0bdb6e-8aff-478b-a9bc-29732ec3e99c

Last Card Change

2020-04-14