Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs
This commit is contained in:
@@ -0,0 +1,8 @@
|
||||
# KingsPawn Spyware Indicators of Compromise
|
||||
This folder contains indicators of compromise (in STIX v2 format) generated by the iMazing team for the KingsPawn spyware from QuaDream, which was discovered by Citizen Lab and Microsoft.
|
||||
|
||||
The spyware targeted iOS 14 using a zero-click exploit called _ENDOFDAYS_. Further details can be found here:
|
||||
* https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/
|
||||
* https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
|
||||
|
||||
These indicators of compromise are based on the list of domains provided in Microsoft's article, as well as the process names mentioned in both Citizen Lab and Microsoft's articles.
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user