An Analysis of Infrastructure linked to the Hagga Threat Actor
released on 2022-07-14 @ 09:42:07 AM
TeamCymru began tracking the threat actor Hagga in late 2021 following the release of an analysis by Z-Lab (Yoroi Security’s malware research team). Z-Lab were tracking a worldwide campaign to distribute the Agent Tesla information stealer through an elusive multi-stage infection process. In their analysis, they shared the IOCs for this campaign, including a single hardcoded IP address (69.174.99.181) and a common URL directory pattern for the identified C2 panels.
This blog will describe how TeamCymru were able to pivot in threat telemetry, using these IOCs as seeds, to identify several other C2s used by this threat actor, ultimately leading us to a backend MySQL server.