SYMBOLCOMMON_NAMEaka. SYNONYMS
win.xtunnel_net (Back to overview)

X-Tunnel (.NET)

Actor(s): APT28


This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.

References
2018-10-04NCSC UKNCSC UK
@online{uk:20181004:indicators:65560f3, author = {NCSC UK}, title = {{Indicators of Compromise for Malware used by APT28}}, date = {2018-10-04}, organization = {NCSC UK}, url = {https://www.ncsc.gov.uk/alerts/indicators-compromise-malware-used-apt28}, language = {English}, urldate = {2020-01-07} } Indicators of Compromise for Malware used by APT28
X-Tunnel (.NET)

There is no Yara-Signature yet.