While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additional modules and/or malware from the Command and Control server. This then is a surveillance attack in progress and has been dubbed ‘Big Bang’ due to the attacker’s fondness for the ‘Big Bang Theory’ TV show, after which some of the malware’s modules are named.
There are currently no families associated with this actor.
|2018-07-08 ⋅ Check Point Research ⋅ |
APT Attack In the Middle East: The Big Bang
Micropsia The Big Bang
|2017-06-19 ⋅ Cisco Talos ⋅ |
Delphi Used To Score Against Palestine
The Big Bang