CORESHELL (3b193f62-2b49-4eff-bdf4-501fb8a28274)
CORESHELL is a downloader used by APT28. The older versions of this malware are known as SOURFACE and newer versions as CORESHELL.[FireEye APT28] [FireEye APT28 January 2017]
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
APT28 (5b1a5b9e-4722-41fc-a15d-196a549e3ac5) | Tidal Groups | CORESHELL (3b193f62-2b49-4eff-bdf4-501fb8a28274) | Tidal Software | 1 |