BOOKWORM
S1226 · Windows
BOOKWORM is a modular trojan known to be leveraged by Mustang Panda and was first observed utilized in 2015. BOOKWORM was later updated in late 2021 and the fall of 2022 to launch shellcode represented as UUID parameters.
ATT&CK S1226
Sigma rules0
YARA rules0
Live IOCs0