Octopus-infested seas of Central Asia
#1
Information 
[Image: 181012-octopus-1.png]
Quote:For the last two years we have been monitoring a Russian-language cyberespionage actor that focuses on Central Asian users and diplomatic entities. We named the actor DustSquad and have provided private intelligence reports to our customers on four of their campaigns involving custom Android and Windows malware. In this blogpost we cover a malicious program for Windows called Octopus that mostly targets diplomatic entities.

The name was originally coined by ESET in 2017 after the 0ct0pus3.php script used by the actor on their old C2 servers. We also started monitoring the malware and, using Kaspersky Attribution Engine based on similarity algorithms, discovered that Octopus is related to DustSquad, something we reported in April 2018. In our telemetry we tracked this campaign back to 2014 in the former Soviet republics of Central Asia (still mostly Russian-speaking), plus Afghanistan.

In the case of Octopus, DustSquad used Delphi as their programming language of choice, which is unusual for such an actor. Among others exceptions are the Russian-language Zebrocy (Sofacy’s Delphi malware), the Hindi-language DroppingElephant and the Turkish-language StrongPity. Although we detected Octopus victims that were also infected with Zebrocy/Sofacy, we didn’t find any strong similarities and we don’t consider the two actors to be related.
Full reading: https://securelist.com/octopus-infested-...sia/88200/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Messages In This Thread
Octopus-infested seas of Central Asia - by harlan4096 - 16 October 18, 06:51

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Tor Browser 15.0.14
Tor Browser 15.0.1...harlan4096 — 06:07
About that new SecureBoot folder in C:/W...
If you’ve noticed ...harlan4096 — 06:05
CrystalDiskInfo 9.9.0 [2026/05/18]
CrystalDiskInfo 9....harlan4096 — 06:43
Adobe Acrobat Reader DC 2026.001.21563
Adobe Acrobat Read...harlan4096 — 06:42
FastCopy 5.11.3
FastCopy 5.11.3: ...harlan4096 — 06:40

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>