[2/5] ScarredManticore utilizes #LIONTAIL, an advanced malware framework, consisting of passive loaders and memory resident modules. Some of those use undocumented functionalities of the HTTP.sys driver to load incoming payloads also referred to as #ShroudedSnooper. [image]
Scarred Manticore ~ OilRig/APT34 & DEV-0861 Overview of code and capabilities evolution of multiple malware versions used by Scarred Manticore. https://research.checkpoint.com/ ... [image]
‘... progress the Iranian actors have undergone over the last few years. The techniques utilized in recent Scarred Manticore operations are notably more sophisticated compared to previous activities CPR has tied to Iran’. https://research.checkpoint.com/ ...
[1/5] CPR in collaboration with @sygnia_labs has been tracking #ScarredManticore, one of the most sophisticated Iranian threat actors uncovered to date. Attributed to the MOIS, it is linked to some of the most impactful Iranian intrusions in recent years. https://research.checkpo…