TiltedTemple — APT Profile
One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activities have been linked to the exploitation of vulnerabilities in Zoho ManageEngine ADSelfService Plus and ServiceDesk Plus.Also tracked as
DEV-0322
IntelFusions coverage (1)
- TA505 Pivots from Phishing to CVE-2021-35211 SolarWinds Serv-U Exploitation: Cobalt Strike Delivery and RegIdleBackup COM Handler Hijacking for FlawedGrace RAT Persistence 2026-02-16 · Ransomware
Vendor research
- Microsoft discovers threat actor targeting SolarWinds Serv-U software with 0-day exploit Microsoft (MSTIC / MSRC)
- Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer Unit 42 (Palo Alto Networks)
- SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors Unit 42 (Palo Alto Networks)
- APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk Plus Unit 42 (Palo Alto Networks)