Crouching Yeti
Active
 
Backdoor, Remote administration tool
January 2014
 
Windows
2010
 
2,001-3,000
TOP TARGETED COUNTRIES:
USA, Spain, Japan, Germany, France, Italy, Turkey, Ireland, Poland, China
  • Social engineering
  • Exploits
  • Watering hole attacks
  • Trojanized software installers
  • Data theft
  • Interest in OPC/SCADA. Trojanized software used to administer remote OPC servers as well as modules to scan networks for OPC servers.
  • Industrial/machinery
  • Manufacturing
  • Pharmaceutical
  • Construction
  • Education
  • Information technology
  • Russian-speaking authors
The blog post and research paper are available at Securelist.com