#Atharvan

Malware/Tool

2023-02-23 • Clasiopa: New Group Targets Materials Research

Atharvan is a custom backdoor associated with Clasiopa, a threat group observed targeting a materials-research organization in Asia. The surrounding intrusion included signs of brute-force access against public-facing servers. Atharvan communicates with a hardcoded command-and-control endpoint hosted in cloud infrastructure and sends data through HTTP POST requests. Its traffic uses a Microsoft-themed Host header to make malicious communications resemble ordinary software-update activity, illustrating the actor's use of trusted branding to disguise network behavior.

Tagged Reports

« Back