Crimson

MITRE ATT&CK: S0115 View on attack.mitre.org

Aliases: MSIL/Crimson, Crimson

First seen
2016-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
39 (13 malicious)
Last IoC activity
2026-08-31 20:39:22
Profile updated
2026-07-07 15:46:39

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:in country_code:pk

Context

Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016.

Recent IoC activity

13 malicious indicators in Maltiverse are attributed to Crimson (S0115). The 13 most recently updated:

TypeIndicatorUpdatedSources
hostname sub172.duckdns.org 2026-09-02 1
hostname arvnd.duckdns.org 2025-06-20 1
file sample SecuriteInfo.com.Win32.MalwareX-gen.22632.19376.exe 2025-05-08 2
file sample SecuriteInfo.com.Win32.MalwareX-gen.25339.3415.exe 2025-05-08 2
file sample SecuriteInfo.com.Win32.MalwareX-gen.31399.5314.exe 2025-05-08 2
file sample SecuriteInfo.com.BackDoor.CrimsonNET.14.26407.16542 2025-04-15 1
file sample bef8327c64ee14576b2f9a800d74b5a6.exe 2025-02-18 1
file sample 164f7996b586499ba1ebdb8e10f5581e012025.xlam 2025-02-16 1
file sample jivarthr edis.exe 2025-02-16 1
file sample jivarthr edis.exe 2025-02-16 1
file sample jivarthr edis.exe 2025-02-16 1
file sample b4819738a277090405f0b5bbcb31d5dd3115f7026401e5231df727da0443332a.bin 2025-02-14 1
file sample 9b75e3e28f95345937f507b281e2a32a.exe 2023-02-23 2

Detection coverage

  • 427 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • File Deletion (attack-pattern)
  • System Time Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Keylogging (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Audio Capture (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Process Discovery (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Data from Removable Media (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • proofpoint.com — Proofpoint Operation Transparent Tribe Threat Insight En (report)
  • Kaspersky — 98127 (report)
  • MITRE ATT&CK — S0115 (report)
  • connect-trojan.net — Crimson Rat 3.0.0 (report)

External references