Introduction
Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing Salome interesting and relevant is the attackerβs penchant for leveraging HackingTeam RCS implants compiled after the public breach.
Activities and Tactics
Targeted Sectors: Think Tanks, Government, Administration
Suspected Victims: Ukraine
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
Information pending cataloguing.
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- Hacking Team UEFI Rootkit
Attribution and Evidence
Information pending cataloguing.
References
References pending cataloguing.