we began by investigating a new malware family, which we are calling SquirtDanger based on a DLL, SquirtDanger.dll, used in the attacks.
SquirtDanger
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
SquirtDanger in ATT&CK
17 distinct techniquesTechniques
17 techniques T1057 Process Discovery T1564 Hide Artifacts T1204.002 Malicious File T1113 Screen Capture T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1543 Create or Modify System Process T1218 System Binary Proxy Execution T1083 File and Directory Discovery T1497.001 System Checks T1059 Command and Scripting Interpreter T1555 Credentials from Password Stores T1115 Clipboard Data T1041 Exfiltration Over C2 Channel T1053.005 Scheduled Task T1566 Phishing T1189 Drive-by Compromise