SYMBOL | COMMON_NAME | aka. SYNONYMS |
TStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit targeting CVE-2020-15069 (T1203). The actor exhibited odd telemetry behavior indicative of intermittent VPN usage, switching between IP addresses geolocated to Hong Kong and Chengdu. Analysis revealed malware samples for Mac OS X and iOS, as well as IFRAME injection code exploiting a WebAssembly vulnerability (T1189). Additionally, TStark was linked to the development of libsophos.so and the deployment of malicious payloads across their devices.
There are currently no families associated with this actor.
2024-10-31
⋅
Sophos X-Ops
⋅
Pacific Rim timeline: Information for defenders from a braid of interlocking attack campaigns Asnarök Tstark |