Search and filter across all detection sources
207 rules
Google DNS - UNC2452 (Nobelium) APT Group activity
'Detects UNC2452 (Nobelium) APT Group activity.'
APT_APT29_NOBELIUM_Malware_May21_2 [yara]
Detects malware used by APT29 / NOBELIUM
APT_APT29_NOBELIUM_Malware_May21_3 [yara]
APT_APT29_NOBELIUM_Malware_May21_4 [yara]
APT_APT29_NOBELIUM_BoomBox_May21_2 [yara]
Detects BoomBox malware used by APT29 / NOBELIUM
APT_APT29_NOBELIUM_BoomBox_May21_1 [yara]
Detects BoomBox malware as described in APT29 NOBELIUM report
APT_APT29_NOBELIUM_Stageless_Loader_May21_2 [yara]
Detects stageless loader as used by APT29 / NOBELIUM
APT_APT29_NOBELIUM_JS_EnvyScout_May21_1 [yara]
Detects EnvyScout deobfuscator code as used by NOBELIUM group
APT_APT29_NOBELIUM_JS_EnvyScout_May21_2 [yara]
APT_APT29_NOBELIUM_LNK_NV_Link_May21_2 [yara]
Detects NV Link as used by NOBELIUM group
APT_APT29_NOBELIUM_NativeZone_Loader_May21_1 [yara]
Detects NativeZone loader as described in APT29 NOBELIUM report
APT_APT29_NOBELIUM_LNK_Samples_May21_1 [yara]
Detects link file characteristics as described in APT29 NOBELIUM report
APT_APT29_NOBELIUM_BoomBox_PDF_Masq_May21_1 [yara]
Detects PDF documents as used by BoomBox as described in APT29 NOBELIUM report
apt_nobelium_acrobox_downloader_apr2022 [yara_rules]
Detects AcroBox downloader
apt_nobelium_nativezone_gen [yara_rules]
Detects NativeZone used in 2022
MAL_CRIME_Unknown_ISO_Jun21_1 [yara]
Triggers on ISO files that mimick NOBELIUM TTPs, but uses LNK files that call powershell instead.
Request Random Generated SubDomain DGA (Proxy) [splunk-proxy]
Detection of request made to a randomly generated subdomain. - Threat Actor Association: APT29/Nobelium/Cozy Bear, APT34/OilRig
FoggyWeb Backdoor DLL Loading
Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
Certutil Obfuscate_Encode Files [snowflake-crowdstrikefdr_process]
Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti
Powersploit SPN Enumeration [splunk-powershell]
Kerberoast is a series of tools for attacking MS Kerberos implementations. Threat Actor Association: APT29/Nobelium/Cozy Bear Software Association: Cuba, Vice Society #TrendingThreat #Russia #Ukraine Atomics T1558.003 #Test1
Certutil Obfuscate_Encode Files [splunk-edr]
Certutil Obfuscate_Encode Files [splunk-powershell]
Certutil Obfuscate_Encode Files [splunk-sysmon]
Certutil Obfuscate_Encode Files [splunk-winevent]