SoreFang
Description
(NCSC-UK) Malware, dubbed ‘SoreFang’ by the NCSC, is a first stage downloader that uses HTTP to exfiltrate victim information and download second stage malware. The sample analysed by the NCSC contains the same infrastructure as a WellMess sample.
It is likely that SoreFang targets SangFor devices.
Names
Name |
---|
SoreFang |
Category
Malware
Type
- Downloader
Information
- https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development.pdf
- https://us-cert.cisa.gov/ncas/analysis-reports/ar20-198a
- https://securelist.com/apt-trends-report-q3-2020/99204/
Mitre Attack
Malpedia
Alienvault Otx
Other Information
Uuid
ed893e00-126d-4244-8435-830fab699994
Last Card Change
2022-12-30