#NACHOCHEESE
Malware/Tool
2018-10-03 • APT38 Un-usual Suspects
NACHOCHEESE is an APT38 command-line tunneler used to provide shell access to compromised systems. Operators supply delimited command-and-control IP addresses or domain names through its command line, allowing the tool to relay communications across a victim environment. In a documented SWIFT intrusion architecture, NACHOCHEESE sat between the public command-and-control server and an active CHEESETRAY backdoor, helping reach a passive CHEESETRAY instance on a segmented SWIFT Alliance Application Server. Some builds contained poorly translated Russian-language strings that were assessed as likely false flags intended to misdirect investigators.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days