Hagga
Also reported as Aggah and TH-157.
Reports per quarter
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2018-0802 KEV ransomware
- CVE-2023-38831 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Revenge RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Agent Tesla (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Nanocore RAT (Malware Family)
-
Emerging Threats- AgentTesla – A Review and Detection Strategies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emerging Threats- AgentTesla – A Review and Detection Strategies
-
Is Hagga Threat Actor Abusing FSociety Framework -
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Is Hagga Threat Actor Abusing FSociety Framework -
Show all 43 reports Show fewer
-
An Analysis of Infrastructure linked to the Hagga Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Analysis of Infrastructure linked to the Hagga Threat Actor
-
Blame the Messenger- 4 Types of Dropper Malware in Microsoft Office & How to Detect Them
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Blame the Messenger- 4 Types of Dropper Malware in Microsoft Office & How to Detect Them
-
2021 Gorgon Group APT Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 2021 Gorgon Group APT Operation
-
Serverless InfoStealer delivered in Est European Countries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Serverless InfoStealer delivered in Est European Countries
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AGENT TESLAGGAH
-
Aggah Malware Campaign Expands to Zendesk and GitHub to Host Its Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah Malware Campaign Expands to Zendesk and GitHub to Host Its Malware
-
Malicious Campaign Targets Latin America- The seller, The operator and a curious link
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious Campaign Targets Latin America- The seller, The operator and a curious link
-
The -WayBack” Campaign- a Large Scale Operation Hiding in Plain Sight
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The -WayBack” Campaign- a Large Scale Operation Hiding in Plain Sight
-
MalSpam Campaigns Download njRAT from Paste Sites
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MalSpam Campaigns Download njRAT from Paste Sites
-
Aggah Campaign’s Latest Tactics- Victimology, PowerPoint Dropper and Cryptocurrency Stealer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah Campaign’s Latest Tactics- Victimology, PowerPoint Dropper and Cryptocurrency Stealer
-
Cyber-Criminal espionage Operation insists on Italian Manufacturing
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber-Criminal espionage Operation insists on Italian Manufacturing
-
New Cyber Operation Targets Italy- Digging Into the Netwire Attack Chain
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Cyber Operation Targets Italy- Digging Into the Netwire Attack Chain
-
Multistage FreeDom loader used in Aggah Campaign to spread Nanocore and AZORult
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multistage FreeDom loader used in Aggah Campaign to spread Nanocore and AZORult
-
(Ab)using bash-fu to analyze recent Aggah sample
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor (Ab)using bash-fu to analyze recent Aggah sample
-
Aggah- How to run a botnet without renting a Server (for more than a year)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah- How to run a botnet without renting a Server (for more than a year)
-
APT or not APT- What's Behind the Aggah Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT or not APT- What's Behind the Aggah Campaign
-
Hagga of SectorH01 continues abusing Bitly, Blogger and Pastebin to deliver RevengeRAT and NanoCore
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hagga of SectorH01 continues abusing Bitly, Blogger and Pastebin to deliver RevengeRAT and NanoCore
-
The Evolution of Aggah- From Roma225 to the RG Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Evolution of Aggah- From Roma225 to the RG Campaign
-
Aggah Campaign- Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah Campaign- Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
-
Aggah Campaign_ Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah Campaign_ Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Newest first. Details opens the report in Explore.