DSIRF (Knotweed)
DSIRF GmbH (Microsoft codename Knotweed) is an Austrian commercial spyware vendor founded 2016 publicly advertising itself as an information research / forensics / data-driven intelligence services provider but operationally functioning as a private-sector offensive actor (PSOA) developing and selling the Subzero malware toolset to clients while also conducting hack- for-hire operations using its own Knotweed infrastructure per Microsoft MSTIC canonical attribution.
Austrian PSOA hybrid-model attribution via Microsoft MSTIC + MSRC July 28 2022 canonical disclosure ("Microsoft notes that as well as selling the Subzero malware, DSIRF, aka Knotweed, was observed using its own infrastructure in some of the attacks, suggesting more direct involvement in the targeting of victims") with C&C infrastructure + DSIRF-linked GitHub account + DSIRF-issued code signing certificate evidence chain + RiskIQ canonical infrastructure attribution since February 2020 + Citizen Lab / University of Toronto + SOCRadar + TechCrunch + Computer Weekly + ITSecurityGuru + Cyware + Security Boulevard + GridInSoft + Silicon Republic industry coverage.
standalone cluster paralleling variston_heliconia + finfisher_finspy + hacking_team_memento_labs in v0.1.163 commercial spyware / mercenary surveillance vendor operators cell continuation.
operational target profile signature law firms + banks + strategic consultancies with known geographic victims in Austria + Panama + United Kingdom per Microsoft + European + Central American customer base per Microsoft assessment + Microsoft-confirmed unauthorized + malicious targeting (at least one victim confirmed not commissioning red team / penetration testing per Microsoft)
operational attack architecture: (1) cluster-defining Subzero malware toolset hack-for-hire spyware with keylogging + remote shells + screenshots + plugin downloads from C2 server capabilities.
(2) cluster-defining 5-CVE zero-day exploit chain including CVE-2022-22047 Windows CSRSS zero-day (CVSS-rated privilege escalation enabling sandbox escape + system-level code execution, patched July 2022) + CVE-2021- 31199 + CVE-2021-31201 Windows privilege escalation exploit chain combined with CVE-2021-28550 Adobe Reader RCE (all patched June 2021) + CVE-2021- 36948 Windows Update Medic Service privilege escalation 0-day per Microsoft canonical disclosure.
(3) cluster-defining Corelump in- memory primary payload + Jumplump malware loader chain tradecraft with Jumplump downloading and loading Corelump into memory, Corelump loading Subzero payload per Cyware.
(4) signature Excel macro malicious file delivery vector + PDF delivery with Adobe Reader RCE 0-day chain via email attachment with packaged exploit.
(5) cluster-defining DSIRF-issued code signing certificate attribution evidence + DSIRF-linked GitHub account + DSIRF official website + domains forming Microsoft MSTIC evidence chain.
(6) cluster-defining hybrid hack-for-hire + access- as-a-service PSOA model per Microsoft canonical assessment distinguishing DSIRF from pure-vendor PSOAs ("Microsoft used the term PSOA, short for private-sector offensive actor, to describe cyber mercenaries like DSIRF... most PSOAs operate under one or both of two models. The first, access-as-a-service, sells full end-to-end hacking tools to customers for use in their own operations. In the other model, hack-for-hire, the PSOA carries out the targeted operations itself... MSTIC believes that KNOTWEED may blend these models: they sell the Subzero malware to third parties but have also been observed using KNOTWEED- associated infrastructure in some attacks, suggesting more direct involvement")
(7) signature Subzero capabilities device hack including phone + computer + network + IoT device targeting.
(8) signature 2016 founding origin during US presidential election period with Subzero initially advertised as "state trojan analyzing hacking operations" per SOCRadar.
(9) signature alleged Jan Marsalek / Wirecard connection per Security Boulevard reporting context with honest attribution caveat that connection alleged but not corroborated with primary documentary evidence.
cluster fills the Austrian-PSOA + Subzero-malware-toolset + Microsoft- MSTIC-Knotweed-codename + CVE-2022-22047-CSRSS- zero-day + CVE-2021-31199-31201-28550-36948-multi- zero-day-chain + Corelump-Jumplump-loader-tradecraft + hack-for-hire-access-as-a-service-hybrid-model + law-firms-banks-consultancies-targeting + Austria- Panama-UK-known-victims + DSIRF-issued-code- signing-certificate-attribution-evidence position in commercial spyware / mercenary surveillance vendor operators cell.
canonical illustration of Austrian PSOA + hybrid hack-for-hire / access-as- a-service model + multi-zero-day-chain capability + law firms/banks/consultancies-targeting + Corelump/ Jumplump in-memory tradecraft + Microsoft MSTIC C&C-GitHub-certificate evidence chain attribution methodology cited in essentially all subsequent commercial spyware industry analyses through 2016- 2026 period.