Crimson
MITRE ATT&CK: S0115 View on attack.mitre.org
Aliases: MSIL/Crimson, Crimson
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 39 (13 malicious)
- Last IoC activity
- 2026-08-31 20:39:22
- Profile updated
- 2026-07-07 15:46:39
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:in country_code:pk
Context
Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016.
Recent IoC activity
13 malicious indicators in Maltiverse are attributed to Crimson (S0115). The 13 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | sub172.duckdns.org | 2026-09-02 | 1 |
| hostname | arvnd.duckdns.org | 2025-06-20 | 1 |
| file sample | SecuriteInfo.com.Win32.MalwareX-gen.22632.19376.exe | 2025-05-08 | 2 |
| file sample | SecuriteInfo.com.Win32.MalwareX-gen.25339.3415.exe | 2025-05-08 | 2 |
| file sample | SecuriteInfo.com.Win32.MalwareX-gen.31399.5314.exe | 2025-05-08 | 2 |
| file sample | SecuriteInfo.com.BackDoor.CrimsonNET.14.26407.16542 | 2025-04-15 | 1 |
| file sample | bef8327c64ee14576b2f9a800d74b5a6.exe | 2025-02-18 | 1 |
| file sample | 164f7996b586499ba1ebdb8e10f5581e012025.xlam | 2025-02-16 | 1 |
| file sample | jivarthr edis.exe | 2025-02-16 | 1 |
| file sample | jivarthr edis.exe | 2025-02-16 | 1 |
| file sample | jivarthr edis.exe | 2025-02-16 | 1 |
| file sample | b4819738a277090405f0b5bbcb31d5dd3115f7026401e5231df727da0443332a.bin | 2025-02-14 | 1 |
| file sample | 9b75e3e28f95345937f507b281e2a32a.exe | 2023-02-23 | 2 |
Detection coverage
- 427 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Security Software Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- File Deletion (attack-pattern)
- System Time Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Time Based Checks (attack-pattern)
- Keylogging (attack-pattern)
- Web Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Audio Capture (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Process Discovery (attack-pattern)
- Local Email Collection (attack-pattern)
- Modify Registry (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Data from Removable Media (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- System Location Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- C0011 (campaign)
- Transparent Tribe (threat-actor)
Related threat objects
- Crimson RAT (malware)
Reports & references
- proofpoint.com — Proofpoint Operation Transparent Tribe Threat Insight En (report)
- Kaspersky — 98127 (report)
- MITRE ATT&CK — S0115 (report)
- connect-trojan.net — Crimson Rat 3.0.0 (report)