#CryptoSpy

Malware/Tool

2022-06-15 • TTP Tuesday: APT38 CryptoSpy

CryptoSpy names a Prelude Operator training implant created to emulate initial access associated with APT38's TraderTraitor activity, rather than a confirmed operational malware family used by APT38. The Go-based graphical application imitated a cryptocurrency price tool and offered an update button that downloaded and launched a Pneuma agent. It resolved callback configuration from a local config.json file or its own filename, then connected to a Redirector or Operator instance.

Tagged Reports

« Back