ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Castov

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Castov

NamesCastov
CategoryMalware
TypeCredential stealer, Info stealer
DescriptionAlso in 2013, researchers spotted a piece of malware called Castov (Downloader.Castov and Infostealer.Castov) targeting South Korean financial institutions and their customers. In these attacks, which are also believed to originate from Lazarus, Castov was used to steal passwords, account details, and digital certificates from the computers it infected. Castov (Trojan.Castov) was also used in further DDoS attacks against South Korean targets in June 2013.
Information<https://medium.com/threat-intel/lazarus-attacks-wannacry-5fdeddee476c>

Last change to this tool card: 19 April 2020

Download this tool card in JSON format

Previous: Casper
Next: Catchamas

All groups using tool Castov

ChangedNameCountryObserved

APT groups

 Lazarus Group, Hidden Cobra, Labyrinth ChollimaNorth Korea2007-Spring 2021X

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key