Clasiopa

2023-02-23 • SymantecClasiopa: New Group Targets Materials Research

Clasiopa is a threat cluster identified by Symantec after it targeted a materials-research organization in Asia; at the time of reporting there was no firm evidence establishing the group's origin or the identity of any sponsor. The group relies on a distinct, largely custom toolset rather than commodity malware, centered on the Atharvan backdoor alongside a modified version of the publicly available Lilith remote access trojan, a file-listing and exfiltration tool called Thumbsender, and a custom proxy tool. Observed tradecraft includes likely initial access through brute-force attacks on public-facing servers, disabling of endpoint security software, clearing of system and event logs, and exfiltration of file listings via disguised archive files. Backdoor command-and-control traffic is disguised as legitimate software-update traffic and protected with a simple custom encryption scheme. Analysts noted possible false-flag indicators, including a Hindi-language mutex string and an India-referencing archive password, but assessed these could be deliberately planted misdirection rather than genuine attribution clues.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster