SURTR

SURTRSURTR

Description

The Citizen Lab analyzed a malicious email sent to Tibetan organizations in June 2013. The email in question purported to be from a prominent member of the Tibetan community and repurposed content from a community mailing list. Attached to the email were what appeared to be three Microsoft Word documents (.doc), but which were trojaned with a malware family we call “Surtr”.1 All three attachments drop the exact same malware. We have seen the Surtr malware family used in attacks on Tibetan groups dating back to November 2012.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Sepulcher
Software
NetTraveler
Software
SunOrcal
Software
Suri
Software
Rurktar
Sub-technique
Spearphishing Attachment
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.