Common Information
Type Value
Value
rule apt_41_phantom_implant {
	meta:
		author = "Felipe Duarte, Security Joes"
		description = "Detects APT 41 Phantom Implant"
		sha256_reference = "3df75113ff7a9c2158ff991e1f4e1c2dcc5bd19f41caa07f1dc0aabc4f872bed"
	strings:
		$str1 = { 8B C8 69 DB ?? ?? ?? ?? 8A C3 C1 EB 08 41 30 03 49 FF C3 48 FF C9 }
	condition:
		$str1
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2024-10-21 18 The Silent Game: Sophisticated Threat Actors Targeting Gambling Industry