Also known as: middle, the Register of Actions, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, Hayes command set, hang up, change connection settings, U2DiskWatch, control module
Attor operates as a modular loader that can ingest custom DLLs to extend its functionality, enabling the operator to tailor payloads for specific targets. Core capabilities include staging malware‑collected data in a dedicated upload folder before encrypting it with Blowfish and RSA, then transmitting it via an encrypted Tor circuit over TCP port 21. The adversary also hides artifacts by setting file attributes to HIDDEN, SYSTEM or ARCHIVE and employs process injection into both 32‑bit and 64‑bit processes for privilege escalation and evasion. In addition to stealth, Attor demonstrates advanced persistence mechanisms: writing a logon‑script entry in the registry as well as modifying SafeBoot Minimal keys so that its custom services run even when Windows is booted in safe mode. It further detects virtualization or emulation environments, terminating itself if such conditions are detected. The platform’s reconnaissance suite includes audio capture, keystroke logging within injected windows, automated system data collection (screenshots, clipboard, scheduled tasks), and process discovery via native API calls. All of these functions are coordinated through a central command‑and‑control agent that communicates covertly via Tor, ensuring operational anonymity.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Attor is a sophisticated Windows‑based espionage platform that blends stealth, persistence and data‑stage capabilities. It leverages a loadable plugin architecture to tailor operations against high‑profile sectors such as government, finance and critical infrastructure, while using covert C2 channels over port 21 and Tor for exfiltration. The operator’s focus appears balanced between financial gain and strategic intelligence gathering, with evidence of persistence through logon scripts, SafeBoot modifications, and DLL injection.
Goals & Targeting
Attor’s strategic objectives appear twofold: (1) to secure financial benefits by delivering stolen data to affiliates or using it for ransomware‑like demands; and (2) to acquire actionable intelligence on governmental, financial, and critical infrastructure entities. The actor routinely targets a wide array of sectors—government, finance, defense, telecom, energy, healthcare, transportation—and geographically diverse regions including the US, Russia, Ukraine, China, India, and Brazil. Such broad targeting suggests an agenda that blends economic exploitation with political or strategic objectives, possibly reflecting a nation‑state affiliated group.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
No campaigns linked yet.
No observed data linked yet.
40
Techniques
51
Tools
0
Campaigns
44
IOCs
0
Observed Data
9
Tactics