<img src="https://ws.zoominfo.com/pixel/csEHmvjEA1iScHExXGZE" width="1" height="1" style="display: none;">

The Week in Review from Stamus Labs

Welcome to the weekly threat detection update report from Stamus Networks. Each week, you will receive this email with a summary of the updates.

 

Current Stamus Threat Intelligence (STI) release version: 1738

 

This week, in addition to daily ruleset and IOC updates, we provided Stamus Security Platform customers with the following improved defense(s):

 

  • New threat detection(s) added [1]: 2 (TonRAT, OnionDrop)
  • New methods additions on existing threats [2]: 258
  • New detection methods in total [3]: 264

 

Note: a "method" as referenced below, is a discrete detection vector for a given threat.

 

New Threat(s) Detected

The following detections were added to your Stamus NDR this past week:

 

OnionDrop (Loader)

OnionDrop is a significant threat with a sophisticated evasion architecture that exceeds nation-state tooling. The focus on high-profile threats leaves a gap in addressing commoditized malware like OnionDrop.

 

  • Total number of detection methods: 3
  • Kill chain phase(s): command and control
  • MITRE ATT&CK: T1071

 

TonRAT (RAT)

TonRAT is a malware acting as a RAT and downloader, utilizing the blockchain system The Open Network (TON) and Obfuscator.io's VM Obfuscation. Code is extensive and obfuscated.

 

TonRAT - Malpedia

 

  • Total number of detection methods: 3
  • Kill chain phase(s): delivery, command and control
  • MITRE ATT&CK: T1071

 

Major Detection Changes

The following detections were updated this past week with changes to kill chain phase(s) or MITRE ATT&CK tactic(s)/technique(s):

 

APT28 (APT)

APT28, linked to Russia's Main Intelligence Directorate, compromised the Hillary Clinton campaign, DNC, and DCCC in 2016 to interfere with U.S. election. Active since 2004.

 

  • Added kill chain phase(s): delivery, installation, command and control
  • Previously supported kill chain phase(s): delivery, exploitation, command and control, actions on objectives
  • MITRE ATT&CK added: T1071
  • Previously existing MITRE ATT&CK: T1018, T1041, T1071
  • Methods added: 7

 

ClickFix (Phishing)

In April 2024, researchers found compromised sites leading to an iframe on pley[.]es showing an error message. The payload domain was taken offline, preventing infection. Later, the iframe was replaced with the ClearFake inject.

 

  • Added kill chain phase(s): delivery
  • Previously supported kill chain phase(s): delivery, exploitation, installation, command and control
  • MITRE ATT&CK added: T1189
  • Previously existing MITRE ATT&CK: T1027, T1036, T1071, T1102, T1105, T1189, T1190, T1566
  • Methods added: 3

 

Fake Service (Phishing)

Phishing involves scammers posing as familiar companies to obtain personal information. Consumers should avoid responding to suspicious emails requesting personal or financial details to prevent falling victim to these scams.

 

  • Added kill chain phase(s): delivery, command and control
  • Previously supported kill chain phase(s): delivery, installation, command and control, actions on objectives
  • MITRE ATT&CK added: T1071
  • Previously existing MITRE ATT&CK: T1036, T1041, T1071, T1105, T1189, T1219, T1566
  • Methods added: 5

 

Hqwar (Data Theft)

Trojan-Banker programs steal bank account information and other data, then transfer it to malicious users. Stolen data can be transmitted through email, FTP, the web, or other methods.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): command and control, actions on objectives
  • Previously existing MITRE ATT&CK: T1041, T1071
  • Methods added: 3

 

LandUpdate808 (Trojan)

Fake update variants like SocGholish, Clear Fake, Smart Ape, and ClickFix are being tracked by a collaboration introducing the LandUpdate808 Fake Update Variant.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): delivery, exploitation, command and control, actions on objectives
  • MITRE ATT&CK added: T1189
  • Previously existing MITRE ATT&CK: T1071, T1105, T1189
  • Methods added: 12

 

Lumma (Data Theft)

Lumma is a C-based information stealer sold on Russian underground forums and Telegram by LummaC since August 2022. It targets cryptocurrency wallets and has file grabber capabilities.

 

  • Added kill chain phase(s): command and control, actions on objectives
  • Previously supported kill chain phase(s): delivery, installation, command and control, actions on objectives
  • MITRE ATT&CK added: T1071
  • Previously existing MITRE ATT&CK: T1005, T1071, T1105, T1573
  • Methods added: 45

 

MageCart (Data Theft)

FIN6 or Magecart is a cybercrime group that steals payment card data from PoS systems in hospitality and retail, selling it on underground markets for profit.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): delivery, command and control, actions on objectives
  • MITRE ATT&CK added: T1041
  • Previously existing MITRE ATT&CK: T1071, T1105, T1587
  • Methods added: 3

 

Malicious DGA Domain (Generic CnC)

Malicious domains are used by threat actors for malware spreading and phishing. C2 servers are established worldwide to evade detection. DGA generates domain names for command and control, challenging security professionals. Stamus Networks offers specialized detection methods.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): command and control
  • Methods added: 72

 

Misconfigured Application (Potential data leakage)

Misconfigured applications open the door for data breaches, unauthorized access, financial losses, and reputational damage. Vulnerabilities provide easy entry points for attackers, leading to costly breaches and compromised systems.

 

  • Added kill chain phase(s): pre condition
  • Previously supported kill chain phase(s): pre condition
  • Methods added: 7

 

NetSupport RAT (RAT)

Remote Access Trojans allow covert surveillance and unauthorized access to victim PCs, collecting keystrokes, passwords, screenshots, and more. They differ from keyloggers by providing remote access capabilities to attackers.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): exploitation, installation, command and control, actions on objectives
  • MITRE ATT&CK added: T1105
  • Previously existing MITRE ATT&CK: T1071, T1105
  • Methods added: 1

 

Powershell (Lateral Movement)

Adversaries can abuse PowerShell for execution, discovery, and code running. Examples include Start-Process and Invoke-Command cmdlets, requiring administrator permissions for remote connections.

 

  • Added kill chain phase(s): delivery
  • Previously supported kill chain phase(s): delivery, installation, command and control, actions on objectives
  • MITRE ATT&CK added: T1105
  • Previously existing MITRE ATT&CK: T1027, T1041, T1071, T1105
  • Methods added: 5

 

SocGholish (Social Engineering)

Malwarebytes found a new social engineering toolkit that uses compromised websites to perform advanced fingerprinting checks and deliver the NetSupport RAT payload.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): reconnaissance, delivery, exploitation, command and control, actions on objectives
  • Previously existing MITRE ATT&CK: T1027, T1071, T1189
  • Methods added: 21

 

TA2726 (APT)

TA2726 serves as a TDS for TA2727 and TA569, distributing SocGholish malware that pretends to be a browser update on compromised sites.

 

  • Added kill chain phase(s): delivery, command and control
  • Previously supported kill chain phase(s): command and control
  • MITRE ATT&CK added: T1189
  • Previously existing MITRE ATT&CK: T1189
  • Methods added: 6

 

TA2727 (APT)

Cybercriminal group TA2727 collaborates with others for financial gain, purchasing online traffic to disseminate malware. Proofpoint identified them in an attack campaign delivering malicious payloads via compromised websites in North America.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): command and control
  • Methods added: 6

 

TA395 (APT)

Cybersecurity firms report multiple groups tied to India, including TA397, TA399, and TA395, linked to the Sloppy Lemming threat group, targeting individuals and critical infrastructure.

 

  • Added kill chain phase(s): command and control, actions on objectives
  • Previously supported kill chain phase(s): command and control, actions on objectives
  • MITRE ATT&CK added: T1071
  • Previously existing MITRE ATT&CK: T1041
  • Methods added: 10

 

TA425 (APT)

Proofpoint has identified an Indian APT actor known as TA425.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): command and control
  • MITRE ATT&CK added: T1041
  • Previously existing MITRE ATT&CK: T1071
  • Methods added: 9

 

TrojanSpy-Android (Data Theft)

Malicious programs in the Trojan-Spy.AndroidOS.Agent family covertly send data from infected Android devices to criminals.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): delivery, installation, command and control, actions on objectives
  • Previously existing MITRE ATT&CK: T1041, T1071, T1583
  • Methods added: 2

 

XWorm (RAT)

Cyble research labs found a malware developer advertising a powerful Windows RAT on the dark web during a threat-hunting exercise.

 

  • Added kill chain phase(s): command and control
  • Previously supported kill chain phase(s): delivery, command and control
  • MITRE ATT&CK added: T1573
  • Previously existing MITRE ATT&CK: T1071, T1573
  • Methods added: 41

 

Other Threat Detection Update(s)

The following threat detection(s) were improved this past week with new or updated threat methods.

 

Name of threat New coverage Total coverage Last updated
  New methods Kill chain phases Protocols Methods Kill chain phases Protocols  
APT28 7 delivery, installation, command and control http 806 delivery, exploitation, installation, command and control, actions on objectives dns, http, http1, tcp, tcp-pkt, tls 2026-09-04
ClickFix 3 delivery dns, http, tls 820 delivery, exploitation, installation, command and control dns, http, tls 2026-09-10
Fake Service 5 delivery, command and control dns, http 213 delivery, installation, command and control, actions on objectives dns, http, http1, tcp, tls 2026-09-04
Hqwar 3 command and control dns, http, tls 176 command and control, actions on objectives dns, http, http1, tls 2026-09-04
LandUpdate808 12 command and control dns, http, tls 1204 delivery, exploitation, command and control, actions on objectives dns, http, tls 2026-09-09
Lumma 45 command and control, actions on objectives dns, http, tls 8671 delivery, installation, command and control, actions on objectives dns, http, tls 2026-09-10
MageCart 3 command and control dns, http, tls 527 delivery, command and control, actions on objectives dns, http, tls 2026-09-03
Malicious DGA Domain 72 command and control http, tls 349 command and control http, tls 2026-09-09
Misconfigured Application 7 pre condition tcp 33 pre condition smtp, tcp 2026-09-09
NetSupport RAT 1 command and control http 242 exploitation, installation, command and control, actions on objectives dns, http, tls 2026-09-04
OnionDrop 3 command and control http 3 command and control http 2026-09-04
Powershell 5 delivery http 77 delivery, installation, command and control, actions on objectives dns, http, http1, tcp, tcp-pkt, tls 2026-09-10
SocGholish 21 command and control dns, http, tls 2488 reconnaissance, delivery, exploitation, command and control, actions on objectives dns, http, tcp, tcp-pkt, tls 2026-09-09
TA2726 6 delivery, command and control http 192 delivery, command and control dns, http, tls 2026-09-08
TA2727 6 command and control dns, http, tls 21 command and control dns, http, tls 2026-09-08
TA395 10 command and control, actions on objectives http, tls 25 command and control, actions on objectives dns, http, tcp-pkt, tls 2026-09-04
TA425 9 command and control dns, http, tls 28 command and control dns, http, tls 2026-09-03
TonRAT 3 delivery, command and control http 3 delivery, command and control http 2026-09-04
TrojanSpy-Android 2 command and control dns 1574 delivery, installation, command and control, actions on objectives dns, http, http1, tcp, tls 2026-09-04
XWorm 41 command and control tcp-pkt 5782 delivery, command and control dns, http, tcp, tcp-pkt, tls 2026-09-04

 

Additional Resources

Schedule a Demo of Clear NDR

Request a Demo