8 lines
795 B
Markdown
8 lines
795 B
Markdown
|
|
# KingsPawn Spyware Indicators of Compromise
|
||
|
|
This folder contains indicators of compromise (in STIX v2 format) generated by the iMazing team for the KingsPawn spyware from QuaDream, which was discovered by Citizen Lab and Microsoft.
|
||
|
|
|
||
|
|
The spyware targeted iOS 14 using a zero-click exploit called _ENDOFDAYS_. Further details can be found here:
|
||
|
|
* https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/
|
||
|
|
* https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
|
||
|
|
|
||
|
|
These indicators of compromise are based on the list of domains provided in Microsoft's article, as well as the process names mentioned in both Citizen Lab and Microsoft's articles.
|