Asnarök is a threat actor known for exploiting CVE-2020-12271 to deploy the Asnarök Trojan via web shell.
Analyst brief
Asnarök is a threat actor that exploited CVE-2020-12271 and used command injection privilege escalation to gain root access and install the Asnarök Trojan. It targets devices by deploying a web shell that does not reach out to external C2 for commands, demonstrating evolving TTPs. The actor used an IC.sh script to steal local user account data. Defenders should prioritize patching vulnerabilities disclosed by bug bounty researchers and monitor for anomalous shell processes, unauthorized root access, and data exfiltration via scripts.
Asnarök
Personal Panda
unknown
Asnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asnarök Trojan and demonstrated significant changes in TTPs, including the deployment of a web shell that did not reach out to external C2 for commands. X-Ops identified a patient-zero device linked to the attack and observed the use of an IC.sh script that stole local user account data. The actor's activities were linked to a broader pattern of malicious exploit research and targeted vulnerabilities disclosed by bug bounty researchers.