SlingshotSlingshot

Also known as: Slingshot

Known aliases
1

Profile

While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usually the sign of an advanced APT actor. This turned out to be a malicious loader internally named ‘Slingshot’, part of a new, and highly sophisticated attack platform that rivals Project Sauron and Regin in complexity. While for most victims the infection vector for Slingshot remains unknown, we were able to find several cases where the attackers got access to MikroTik routers and placed a component downloaded by Winbox Loader, a management suite for MikroTik routers. In turn, this infected the administrator of the router. We believe this cluster of activity started in at least 2012 and was still active at the time of this analysis (February 2018).

Aliases· 1

Slingshot

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
ProjectSauron
Actor
Scarab
Software
GravityRAT
Software
Sykipot
Software
Rising Sun
Actor
RAZOR TIGER
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.