Also known as: KNOTWEED, DSIRF
Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using multiple Windows and Adobe 0-day exploits, including one for CVE-2022-22047, which is a privilege escalation vulnerability. Denim Tsunami developed a custom malware called Subzero, which has capabilities such as keylogging, capturing screenshots, data exfiltration, and running remote shells. They have also been associated with the Austrian spyware distributor DSIRF.
Executive Summary
Denim Tsunami, also known as KNOTWEED or DSIRF, is a sophisticated cyber threat actor primarily targeting European and Central American regions through advanced tactics including 0-day exploits and custom malware. Their operations suggest a focus on espionage or financial gain, leveraging tools like Subzero to infiltrate systems for data exfiltration. This group represents a significant risk to sectors with sensitive information.
Goals & Targeting
Denim Tsunami's strategic objectives appear centered around intelligence gathering or financial gain through targeted attacks. Their focus on European and Central American regions suggests they may target government, defense, or corporate entities to acquire sensitive data. The use of advanced exploits indicates a high level of sophistication aiming to disrupt operations or steal information.
Enhanced Description
Denim Tsunami is a cyber threat actor observed targeting European and Central American regions using advanced persistent techniques, including 0-day exploits in Windows and Adobe software. The group has developed custom malware known as Subzero, which features keylogging, screenshot capture, data exfiltration, and remote shell capabilities.Linked to the Austrian spyware distributor DSIRF, Denim Tsunami likely operates with a focus on espionage or financial gain, targeting sectors with sensitive information.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Denim Tsunami has conducted campaigns exploiting零日漏洞 and deploying custom malware. Their operations often involve sophisticated techniques to maintain persistence and stealthily exfiltrate data, targeting industries with high-value intellectual property or sensitive information.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their existence and advanced capabilities, moderate concern about exact TTPs due to limited公开 reports. Further analysis of campaign data would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics