HOPLIGHT

Malware updated 4 months ago (2024-05-04T18:23:11.075Z)
Download STIX
Preview STIX
HOPLIGHT is a type of malware used by the BeagleBoyz criminal group to gain remote access to financial institution networks and steal sensitive information. It is one of several tools used by the group, with HOPLIGHT being particularly useful due to its built-in exfiltration features. The BeagleBoyz likely change their tools over time to maintain access to financial institution networks and interact with those systems. The US Government has recently found HOPLIGHT on victim systems, indicating that the BeagleBoyz are still using it for similar purposes. What sets HOPLIGHT apart from other malware is its ability to create fraudulent Transport Layer Security (TLS) sessions. This makes it difficult to detect and track the malware’s communications, further enabling the BeagleBoyz to carry out their illegal activities. HOPLIGHT shares basic Remote Access Trojan (RAT) functionality with the CROWDEDFLOUNDER implant, which is another tool used by the BeagleBoyz. Several Malware Analysis Reports provide associated Indicators of Compromise (IOCs) for HOPLIGHT and other related malware, including CROWDEDFLOUNDER and ECCENTRICBANDWAGON. These reports can help organizations identify whether their systems have been compromised by any of these malicious programs.
Description last updated: 2023-06-23T14:39:17.956Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the HOPLIGHT Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks | CISA