#Malware Analysis - Executive Summary APT31 (Zirconium
) is long known to use Operational Relay Boxes (ORBs) and compromise routers. This report examines in detail their only publicly known router implant, dubbed « SoWaT ». The implant is capable to function as RAT, a tunnel and a proxy. This group has been subject to several governmental attribution statements, including #Germany, #France, #Norway, #Australia. #internet #reseaux #sysadmin #network #sysops #reseau #cyber #threats #informatique