REF7707
MISP
Tipo:
Unknown
Unknown
Paese:
CN
CN
Prima attivita:
Unknown
Unknown
Dettagli:
REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families such as FinalDraft, GuidLoader, and PathLoader for persistence and lateral movement. The threat actor employs the Microsoft Graph API for C2 communication, blending malicious traffic with legitimate activity to evade detection. Despite their technical sophistication, REF7707 operators exhibited poor operational security, leading to the exposure of their infrastructure and malware. Their tactics enable the extraction of sensitive data, including passwords and Active Directory information, facilitating ongoing espionage activities.
Alias (197)
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
CL-STA-0049
Jewelbug
Metadata
| ID: | 830 |
| Created: | 13/01/2026 17:48 |
| Updated: | 08/03/2026 04:00 |