Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: middle, the Register of Actions, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, Hayes command set, hang up, change connection settings, U2DiskWatch, control module

Description

Attor operates as a modular loader that can ingest custom DLLs to extend its functionality, enabling the operator to tailor payloads for specific targets. Core capabilities include staging malware‑collected data in a dedicated upload folder before encrypting it with Blowfish and RSA, then transmitting it via an encrypted Tor circuit over TCP port 21. The adversary also hides artifacts by setting file attributes to HIDDEN, SYSTEM or ARCHIVE and employs process injection into both 32‑bit and 64‑bit processes for privilege escalation and evasion. In addition to stealth, Attor demonstrates advanced persistence mechanisms: writing a logon‑script entry in the registry as well as modifying SafeBoot Minimal keys so that its custom services run even when Windows is booted in safe mode. It further detects virtualization or emulation environments, terminating itself if such conditions are detected. The platform’s reconnaissance suite includes audio capture, keystroke logging within injected windows, automated system data collection (screenshots, clipboard, scheduled tasks), and process discovery via native API calls. All of these functions are coordinated through a central command‑and‑control agent that communicates covertly via Tor, ensuring operational anonymity.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Manufacturing
Education
Healthcare
Energy
Transportation
Media
Critical infrastructure
Non profit
Information technology
Retail
Aerospace
Hospitality
Legal services
Mining
Pharmaceutical
Aviation
Maritime
Chemical
Nuclear
Gaming
Utilities

Targeted Countries / Regions

US
RU
UA
BR
KR
CN
MX
GB
IN
PL
AU
DE
ES
CA
JP
IL
TR
SY
TW
IT
SA
IR
FR
VN
SG
PK
AE
NL
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 days ago

Executive Summary

Attor is a sophisticated Windows‑based espionage platform that blends stealth, persistence and data‑stage capabilities. It leverages a loadable plugin architecture to tailor operations against high‑profile sectors such as government, finance and critical infrastructure, while using covert C2 channels over port 21 and Tor for exfiltration. The operator’s focus appears balanced between financial gain and strategic intelligence gathering, with evidence of persistence through logon scripts, SafeBoot modifications, and DLL injection.

Goals & Targeting

Attor’s strategic objectives appear twofold: (1) to secure financial benefits by delivering stolen data to affiliates or using it for ransomware‑like demands; and (2) to acquire actionable intelligence on governmental, financial, and critical infrastructure entities. The actor routinely targets a wide array of sectors—government, finance, defense, telecom, energy, healthcare, transportation—and geographically diverse regions including the US, Russia, Ukraine, China, India, and Brazil. Such broad targeting suggests an agenda that blends economic exploitation with political or strategic objectives, possibly reflecting a nation‑state affiliated group.

Enhanced Description

Key Capabilities

  • Loadable plugin architecture for target‑specific customization
  • Staging collected data in a central upload directory before exfiltration
  • Setting file attributes to HIDDEN, SYSTEM or ARCHIVE to conceal evidence
  • Capturing audio from the victim system
  • Launching additional processes via CreateProcessW
  • Loading and executing DLL plugins
  • Persistence through logon script registry entry and SafeBoot Minimal service modification
  • Masquerading as legitimate tasks or services
  • Process injection into 32‑bit and 64‑bit processes for privilege escalation and evasion
  • Detecting virtualized or emulated environments and self‑terminating in those contexts
  • Monitoring free disk usage and auto‑collecting system data
  • Capturing keystrokes within injected process windows
  • Communicating with C2 over TCP port 21 via encrypted Tor channels
  • Downloading additional plugins via remote file copy
  • Encrypting exfiltrated data with Blowfish and RSA

MITRE ATT&CK Tactics

Collection

ATT&CK Techniques

T1074

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: U2DiskWatch
  2. attack.mitre.org — Cited by web research for: T1056
  3. www.welivesecurity.com — Cited by web research for: T1085
  4. www.eset.com — Cited by web research for: Utilities

Intel Summary

40

Techniques

51

Tools

0

Campaigns

44

IOCs

0

Observed Data

9

Tactics

Tags

APT
Government Targeting
espionage
nation-state
government-sector
financial‑gain
China‑linked
multi‑sector
Cobalt Strike
PowerShell
DLL‑loader
GSM fingerprinting

Details

Type
Nation-State
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.