S0042Windows

S0042LOWBALL

Platforms
1
ATT&CK
14.1
References
2

Description

[LOWBALL](https://attack.mitre.org/software/S0042) is malware used by [admin@338](https://attack.mitre.org/groups/G0018). It was used in August 2015 in email messages targeting Hong Kong-based media organizations. (Citation: FireEye admin@338) Documented platforms: Windows. Attributed to ATT&CK group: admin@338. Catalogued in ATT&CK 14.1. 2 references curated.

Platforms· 1

Windows

Attributed to1

TypeTargetConfidenceTier
Groupadmin@338g0018100%live

References

  1. https://attack.mitre.org/software/S0042
  2. https://www.fireeye.com/blog/threat-research/2015/11/china-based-threat.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
StreamEx
Software
HAWKBALL
Software
4H RAT
Software
POORAIM
Software
BADFLICK
Software
SYSCON
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.