Pat Bear, APT-C-37

Description

A subgroup of Syrian Electronic Army (SEA), Deadeye Jackal.

(Qihoo 360) Since October 2015, the Pat Bear Organization (APT-C-37) has launched a well-organized, targeted and persistent attack against the “Islamic State”. Watering hole was used to delivery sample in this attack. The malicious samples were mainly disguised as chat software and some common software in specific fields. This Trojan has many functions such as stealing messages, contacts, WhatsApp and Telegram data, and uploading files using FTP. After reversing and correlation, we found that there is a strong correlation between the Pat Bear Organization and the Golden Rat issue, so this attack activity belongs to another branch of the Syrian Electronic Army.

Names

NameName-Giver
Pat BearQihoo 360
APT-C-37Qihoo 360
Racquet BearCrowdStrike

Country

Syrian Electronic Army

Motivation

  • Information theft and espionage

First Seen

2015

Observed Sectors

Observed Countries

Tools

Information

Other Information

Uuid

01751615-25f0-4ad7-9db9-65abe62e506a

Last Card Change

2023-01-01