WHOIS API
Analysis of Ashen Lepus APT Campaign and AshTag Malware
Pages
8
Time to read
6 mins
Language
English
Pages
8
Time to read
6 mins
Language
English
This technical report details the findings of Palo Alto Networks’ Unit 42 regarding the Ashen Lepus APT campaign, which utilized a new malware suite known as 'AshTag.' The report outlines the group's espionage activities targeting Arabic-speaking government entities and highlights advancements in their operational security and tactics, techniques, and procedures (TTPs). The analysis reveals enhancements in payload encryption, infrastructure obfuscation, and in-memory malware execution aimed at reducing forensic traces. The report identifies 12 subdomains categorized as indicators of compromise (IoCs) and provides a comprehensive examination of 10 unique domains derived from these subdomains. Key findings include the detection of 430 unique client IP addresses, two domains likely to become malicious prior to their classification, and the registration details of the identified domains. The report emphasizes the importance of continuous monitoring and investigation into potential threats, while also acknowledging the evolving nature of cyber threats.