TEXTMATE (49d0ae81-d51b-4534-b1e0-08371a47ef79)
TEXTMATE is a second-stage PowerShell backdoor that is memory-resident. It was observed being used along with POWERSOURCE in February 2017. [FireEye FIN7 March 2017]
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
FIN7 (4348c510-50fc-4448-ab8d-c8cededd19ff) | Tidal Groups | TEXTMATE (49d0ae81-d51b-4534-b1e0-08371a47ef79) | Tidal Software | 1 |