STARWHALE
S1037 · Windows
STARWHALE is Windows Script File (WSF) backdoor that has been used by MuddyWater, possibly since at least November 2021.
there is also a STARWHALE variant written in Golang with similar capabilities. Security researchers have also noted the use of STARWHALE by UNC3313, which may be associated with MuddyWater.
ATT&CK S1037
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0