Hatvibe

Malware updated 7 days ago (2024-11-29T14:53:46.078Z)
Download STIX
Preview STIX
Hatvibe is a custom HTML application loader malware used primarily by the Russia-aligned group TAG-110. This group, known for its operations in line with Russian geopolitical interests, targets government entities, human rights groups, and educational institutions across Asia and Europe. Hatvibe is designed to infiltrate systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, it can disrupt operations, steal personal information, or even hold data hostage for ransom. The malware employs advanced obfuscation techniques such as VBScript encoding and XOR encryption to evade detection. The primary function of Hatvibe is to serve as a loader for deploying additional malicious software, most notably CHERRYSPY. CHERRYSPY is a Python-based backdoor used for data exfiltration and espionage. These two malware tools work in tandem, with Hatvibe establishing initial access and then deploying CHERRYSPY to carry out further attacks. This enables TAG-110 to conduct sophisticated cyber operations against their targets. In summary, the combination of Hatvibe and CHERRYSPY represents a significant cybersecurity threat. The use of these custom malware tools allows TAG-110 to effectively infiltrate targeted systems and conduct operations that align with Russian geopolitical interests. The ability of Hatvibe to deploy CHERRYSPY, coupled with its advanced obfuscation techniques, makes this malware particularly dangerous. It is crucial for organizations within the targeted sectors to maintain robust cybersecurity measures to mitigate the risk posed by these threats.
Description last updated: 2024-11-25T13:45:50.025Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Loader
Python
Malware
Asia
Encryption
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The CherrySpy Malware is associated with Hatvibe. CherrySpy is a potent malware tool used primarily in cyber-attacks against government entities, human rights groups, and educational institutions. This malicious software is part of a broader campaign orchestrated by the Russia-aligned group TAG-110, which targets regions across Asia and Europe. TheUnspecified
3
Source Document References
Information about the Hatvibe Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more