Actor(s): Equation Group
PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks. In May 2020, ESET mentioned that they found mysterious samples of PeddleCheap packed with a custom packer so far exclusively attributed to Winnti.
|2021-12-27 ⋅ |
A Deep Dive into DoubleFeature, Equation Group’s Post-Exploitation Dashboard
Equationgroup (Sorting) Fanny MISTYVEAL PeddleCheap
|2020-05-07 ⋅ Twitter (@ESETresearch) ⋅ |
Tweet on PeddleCheap packed with Winnti packer
|2018-02-06 ⋅ Forcepoint ⋅ |
DanderSpritz/PeddleCheap traffic analysis (Part 1 of 2)
|2017-11-13 ⋅ Obscurity Labs ⋅ |
Match Made In The Shadows: Part 
There is no Yara-Signature yet.