Skip to content

Incidents attributed to:

TiltedTemple

One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers.

One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activities have been linked to the exploitation of vulnerabilities in Zoho ManageEngine ADSelfService Plus and ServiceDesk Plus.

Also known as

DEV-0322, Circle Typhoon.

References


Actor metadata imported from Malpedia (Fraunhofer FKIE).