The Whois Hacking Team

Fecha
20 Jun 2026
Actor
unknown---unmapped-actors
Tipo
Reference
Pais
United States
Sector
-
Confianza
medium
65
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

3IOCs
0TTPs
unknown---unmapped-actorsActor
United StatesPais

The Whois Hacking Team

Que es

The Whois Hacking Team es un grupo de actores anónimos o sin mapeo regional (Unknown / Unmapped Actors) que ha sido identificado como una APT (Advanced Persistent Threat) en análisis de ciberseguridad. Este actor no tiene un nombre oficial asociado, pero sus actividades han sido documentadas a través de fuentes de inteligencia compartida y análisis de red. Los alias mencionados, como http:, www.mcafee.com y wp-dissecting-operation-troy.pdf, sugieren un perfil digital asociado a recursos de seguridad informática.

Contexto

El grupo se ha relacionado con actividades de ciberataques mediante el uso de dominios y archivos compartidos. Según datos verificados por OSINT (Open-Source Intelligence), dos indicadores de compromiso (IOC) han sido identificados:

Tipo: Valor: Contexto:
Dominio www.mcafee.com Asociado al grupo Unknown / Unmapped Actors.
Archivo wp-dissecting-operation-troy.pdf Documentación analítica relacionada con operaciones de ciberataques.

Análisis

El dominio www.mcafee.com podría ser un servidor de comandos (C2) o una fuente de recursos para actividades maliciosas. En cambio, el archivo wp-dissecting-operation-troy.pdf sugiere un material de investigación o reporte sobre operaciones específicas. Ambos elementos reflejan la naturaleza del grupo como actores sin mapeo regional, cuya actividad se basa en recursos y dominios no atribuidos a organizaciones concretas.

Conclusion

El grupo The Whois Hacking Team representa una amenaza de ciberseguridad con un perfil indeterminado. Los indicadores de compromiso disponibles (IOCs) proporcionan evidencia de su actividad, pero la falta de datos detallados limita el entendimiento completo de sus operaciones. La vigilancia sobre dominios y archivos como www.mcafee.com y wp-dissecting-operation-troy.pdf es crucial para mitigar riesgos asociados a este grupo anónimo.

Diamond Model

Adversary
unknown---unmapped-actors
Ver perfil →
Victim
The Whois Hacking Team
www.mcafee.com
United States
Capability
Reference
Infrastructure
www.mcafee.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

8 enlaces
Nodo actual
The Whois Hacking Team
unknown---unmapped-actors · United States
Victima
Persistency: tipically launching ransomware after operation to destroy evidences,Threat Recon.nshc.net alias=SectorA01,http://www.mcafee.com/us/resources/white-papers/wp-dissecting-operation-troy.pdf,http://researchcenter.paloaltonetworks.com/2015/11/tdrop2-attacks-suggest-dark-seoul-attackers-return/,https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf,https://www.alienvault.com/open-threat-exchange/blog/operation-blockbuster-unveils-the-actors-behind-the-sony-attacks,https://www.us-cert.gov/ncas/alerts/TA17-164A,http://www.fsec.or.kr/common/proc/fsec/bbs/21/fileDownLoad/1235.do,https://researchcenter.paloaltonetworks.com/2017/08/unit42-blockbuster-saga-continues/,https://www.crowdstrike.com/blog/unprecedented-announcement-fbi-implicates-north-korea-destructive-attacks/,https://www.us-cert.gov/ncas/alerts/TA17-318A,https://www.us-cert.gov/ncas/alerts/TA17-318B,https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf,https://securingtomorrow.mcafee.com/mcafee-labs/lazarus-resurfaces-targets-global-banks-bitcoin-users/,https://www.darkreading.com/vulnerabilities---threats/lazarus-group-fancy-bear-most-active-threat-groups-in-2017/d/d-id/1330954?print=yes,https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity, https://securelist.com/operation-applejeus/87553/,https://blogs.microsoft.com/on-the-issues/2017/12/19/microsoft-facebook-disrupt-zinc-malware-attack-protect-customers-internet-ongoing-cyberthreats/,https://www.secureworks.com/about/press/media-alert-secureworks-discovers-north-korean-cyber-threat-group-lazarus-spearphishing,https://threatrecon.nshc.net/2019/01/23/sectora01-custom-proxy-utility-tool-analysis/,https://objective-see.com/blog/blog_0x49.html,https://www.sentinelone.com/blog/lazarus-apt-targets-mac-users-poisoned-word-document/,https://blog.alyac.co.kr/2827,https://www.sentinelone.com/blog/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/,https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/,https://www.welivesecurity.com/2020/06/17/operation-interception-aerospace-military-companies-cyberspies/,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operation-north-star-a-job-offer-thats-too-good-to-be-true/,https://www.clearskysec.com/operation-dream-job/,https://blogs.jpcert.or.jp/en/2020/08/Lazarus-malware.html,https://medium.com/s2wlab/analysis-of-threatneedle-c-c-communication-feat-google-tag-warning-to-researchers-782aa51cf74,https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/,https://www.microsoft.com/security/blog/2021/01/28/zinc-attacks-against-security-researchers/,https://www.hvs-consulting.de/lazarus-report/,https://blog.chainalysis.com/reports/lazarus-group-kucoin-exchange-hack,https://securelist.com/lazarus-threatneedle/100803/,https://www.clearskysec.com/wp-content/uploads/2021/05/CryptoCore-Lazarus-Clearsky.pdf,https://blog.alyac.co.kr/3814,https://www.cisa.gov/uscert/ncas/alerts/aa22-108a,https://www.sentinelone.com/blog/lazarus-operation-interception-targets-macos-users-dreaming-of-jobs-in-crypto/,https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/,https://securelist.com/dtrack-targeting-europe-latin-america/107798/,https://www.volexity.com/blog/2022/12/01/buyer-beware-fake-cryptocurrency-applications-serving-as-front-for-applejeus-malware/,https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/,https://labs.withsecure.com/content/dam/labs/docs/WithSecure-Lazarus-No-Pineapple-Threat-Intelligence-Report-2023.pdf,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/,https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/,https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
www.mcafee.com wp-dissecting-operation-troy.pdf
IOC compartido
Victima
Union Panda
Valor:
IOC compartido
Victima
Allegedly attributed the first UEFI rootkit seen in the wild: LoJax (2018)
Valor:
IOC compartido
Victima
0a14b993fdac34f7a05b6d9d22f5fa9cfc711134
Valor:
IOC compartido
Victima
146.59.54.8
Valor:
IOC compartido
Victima
158.51.121.126
Valor:
IOC compartido

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Tipo: Valor: Contexto: VT OffSec SOCRadar
File wp-dissecting-operation-troy.pdf Artefacto observado VT OffSec SOCRadar
Domain www.mcafee.com Dominio victima VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor unknown---unmapped-actors en el blog → Ver unknown---unmapped-actors en IntelTracker → Buscar unknown---unmapped-actors en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Buscar en Shodan → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes