REAVER

REAVERReaver

Description

Unit 42 has discovered a new malware family we’ve named “Reaver” with ties to attackers who use SunOrcal malware. SunOrcal activity has been documented to at least 2013, and based on metadata surrounding some of the C2s, may have been active as early as 2010. The new family appears to have been in the wild since late 2016 and to date we have only identified 10 unique samples, indicating it may be sparingly used. Reaver is also somewhat unique in the fact that its final payload is in the form of a Control panel item, or CPL file. To date, only 0.006% of all malware seen by Palo Alto Networks employs this technique, indicating that it is in fact fairly rare.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
SunOrcal
Software
REvil
Software
Reductor
Software
RevClient
Software
Reetner
Software
Carp Downloader
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.