This is an implant used by APT31 on home routers to utilize them as ORBs.
|2023-09-07 ⋅ Sekoia ⋅ |
My Tea’s not cold. An overview of China’s cyber threat
Melofee PingPull SoWaT Sword2033 MgBot MQsTTang PlugX TONESHELL Dalbit
|2021-11-25 ⋅ imp0rtp3 blog ⋅ |
A Deep Dive Into SoWaT: APT31’s Multifunctional Router Implant
|2021-07-21 ⋅ CERT-FR ⋅ |
INDICATEURS DE COMPROMISSION DU CERT-FR
|2021-07-21 ⋅ Twitter (@bkMSFT) ⋅ |
Tweet on an ANSSI report detailing APT31 intrusions in France
|2021-07-21 ⋅ Twitter (@billyleonard) ⋅ |
Tweet on APT31 using a router implant.
There is no Yara-Signature yet.