Clasiopa
2023-02-23 • Symantec • Clasiopa: New Group Targets Materials Research
Clasiopa is a threat cluster identified by Symantec after it targeted a materials-research organization in Asia; at the time of reporting there was no firm evidence establishing the group's origin or the identity of any sponsor. The group relies on a distinct, largely custom toolset rather than commodity malware, centered on the Atharvan backdoor alongside a modified version of the publicly available Lilith remote access trojan, a file-listing and exfiltration tool called Thumbsender, and a custom proxy tool. Observed tradecraft includes likely initial access through brute-force attacks on public-facing servers, disabling of endpoint security software, clearing of system and event logs, and exfiltration of file listings via disguised archive files. Backdoor command-and-control traffic is disguised as legitimate software-update traffic and protected with a simple custom encryption scheme. Analysts noted possible false-flag indicators, including a Hindi-language mutex string and an India-referencing archive password, but assessed these could be deliberately planted misdirection rather than genuine attribution clues.
-
19
Related Actors
-
162
Related Reports