Skip to content

Hide Navigation Hide TOC

Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e)

Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.(Citation: Google TAG COLDRIVER January 2024)

Cluster A Galaxy A Cluster B Galaxy B Level
Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware Deobfuscate/Decode Files or Information - T1140 (3ccef7ae-cb5e-48f6-8302-897105fbf55c) Attack Pattern 1
Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware 1
Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) Attack Pattern 1
Masquerade Task or Service - T1036.004 (7bdca9d5-d500-4d7d-8c52-5fd47baf4c0c) Attack Pattern Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware 1
Steal Web Session Cookie - T1539 (10ffac09-e42d-4f56-ab20-db94c67d76ff) Attack Pattern Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware 1
Non-Application Layer Protocol - T1095 (c21d5a77-d422-4a69-acd7-2c53c1faa34b) Attack Pattern Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware 1
Ingress Tool Transfer - T1105 (e6919abc-99f9-4c6c-95a5-14761e7b2add) Attack Pattern Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware 1
Spica - S1140 (824a230d-0f6a-4fd0-99df-8d464db2265e) Malware PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) Attack Pattern 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2
Masquerade Task or Service - T1036.004 (7bdca9d5-d500-4d7d-8c52-5fd47baf4c0c) Attack Pattern Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern 2
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) Attack Pattern 2