ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool SLOWDRIFT

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: SLOWDRIFT

NamesSLOWDRIFT
CategoryMalware
TypeReconnaissance, Backdoor, Info stealer, Downloader
Description(FireEye) SLOWDRIFT is a launcher that communicates via cloud based infrastructure. It sends system information to the attacker command and control and then downloads and executes additional payloads.

Lure documents distributing SLOWDRIFT were not tailored for specific victims, suggesting that TEMP.Reaper is attempting to widen its target base across multiple industries and in the private sector.

SLOWDRIFT was seen being deployed against academic and strategic targets in South Korea using lure emails with documents leveraging the HWP exploit.

Recent SLOWDRIFT samples were uncovered in June 2017 with lure documents pertaining to cyber crime prevention and news stories. These documents were last updated by the same actor who developed KARAE, POORAIM and ZUMKONG.
Information<https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf>
MITRE ATT&CK<https://attack.mitre.org/software/S0218/>

Last change to this tool card: 23 April 2020

Download this tool card in JSON format

Previous: Slingshot
Next: SLOWROLL

All groups using tool SLOWDRIFT

ChangedNameCountryObserved

APT groups

XReaper, APT 37, Ricochet Chollima, ScarCruftNorth Korea2012-Dec 2020 HOTX

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key