Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. OceanSalt

OceanSalt

OceanSalt is a Trojan that was used in a campaign targeting victims in South Korea, United States, and Canada.OceanSalt shares code similarity withSpyNote RAT, which has been linked toAPT1.[1]

ID: S0346
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 30 January 2019
Last Modified: 25 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1059.003Command and Scripting Interpreter:Windows Command Shell

OceanSalt can create a reverse shell on the infected endpoint using cmd.exe.[1]OceanSalt has been executed via malicious macros.[1]

EnterpriseT1132.002Data Encoding:Non-Standard Encoding

OceanSalt can encode data with a NOT operation before sending the data to the control server.[1]

EnterpriseT1083File and Directory Discovery

OceanSalt can extract drive information from the endpoint and search files on the system.[1]

EnterpriseT1070.004Indicator Removal:File Deletion

OceanSalt can delete files from the system.[1]

EnterpriseT1566.001Phishing:Spearphishing Attachment

OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments.[1]

EnterpriseT1057Process Discovery

OceanSalt can collect the name and ID for every process running on the system.[1]

EnterpriseT1082System Information Discovery

OceanSalt can collect the computer name from the system.[1]

EnterpriseT1016System Network Configuration Discovery

OceanSalt can collect the victim’s IP address.[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp