TA866 Threat Actor: WasabiSeed & Screenshotter Malware | Proofpoint US

Proofpoint tracks a new financially motivated threat actor cluster, TA866, linked to the Screentime activity that uses custom tools WasabiSeed and Screenshotter to gather victim information via screenshots before deploying additional payloads. The operation leverages a multi-stage chain (email → 404 TDS → JavaScript → MSI → WasabiSeed → Screenshotter, AHK Bot, and Rhadamanthys Stealer) and includes manual actor interventions, domain profiling, and startup persistence to target US and German organizations.
Hashtags: #TA866 #WasabiSeed #Screenshotter #AHKBot #Rhadamanthys #Screentime #Proofpoint

Keypoints

  • TA866 is a newly identified threat actor tracked by Proofpoint, with activity under the “Screentime” cluster observed since Oct 2022 and continuing into 2023.
  • Campaigns are financially motivated and have targeted organizations primarily in the United States, with occasional German-language campaigns.
  • The attacker’s toolkit includes WasabiSeed (VBScript downloader) and Screenshotter (screenshot tool) used to profile victims before delivering follow-on payloads.
  • Initial access occurs via phishing emails with attachments or malicious links, often routed through a Traffic Distribution System (404 TDS) to JavaScript that downloads an MSI package (WasabiSeed installer).
  • Post-exploitation includes AHK Bot components (Looper, Domain Profiler, Stealer Loader) and Rhadamanthys Stealer, with in-memory DLL loading and C2 communications.
  • Proofpoint notes potential historical overlaps with other campaigns (FINTEAM, Trend Micro 2020, Asylum Ambuscade) and highlights manual actor involvement and AD-domain profiling for target selection.

MITRE Techniques

  • [T1566.001] Phishing: Spearphishing Attachment – Initial emails used Publisher attachments with macros and links to JS files to start the attack chain. Quote: ‘Publisher (.pub) attachments with macros’ and ‘URLs linking (via 404 TDS) to Publisher files with macros’
  • [T1059.007] Command and Scripting Interpreter: JavaScript – JavaScript downloaded and, if run by the user, downloads and runs an MSI package. Quote: ‘The JavaScript, if run by the user (such as by double clicking), downloads and runs an MSI package’
  • [T1059.005] Command and Scripting Interpreter: VBScript – WasabiSeed uses an embedded VBS script OCDService.vbs. Quote: ‘The WasabiSeed script’ and ‘OCDService.vbs (WasabiSeed) inside ke.msi’
  • [T1547.001] Boot or Logon Autostart Execution: Startup Folder – WasabiSeed establishes persistence via an LNK file created in the Windows Startup folder. Quote: ‘creates persistence for WasabiSeed via an LNK file “OCDService.lnk” created in the Windows Startup folder’
  • [T1113] Screen Capture – Screenshotter takes desktop screenshots as part of reconnaissance. Quote: ‘takes a JPG screenshot of the user’s desktop and submitting it to a remote C2 via a POST to a hardcoded IP address’
  • [T1041] Exfiltration Over C2 Channel – Screenshotter posts captured images to the C2. Quote: ‘POST to the same C2 address used by WasabiSeed’
  • [T1055] Process Injection – Stealer Loader loads a DLL (Rhadamanthys) from memory. Quote: ‘downloads, decrypts and runs a DLL as bytes from memory’
  • [T1082] System Information Discovery (Domain Profiler) – Domain Profiler determines the machine’s AD domain and reports to C2. Quote: ‘determines the machine’s Active Directory (AD) domain and sends it to the C2’
  • [T1071.001] Application Layer Protocol: Web Protocols – C2 communications and payloads retrieved over HTTP/POST. Quote: ‘to the C2 server’ via HTTP POST

Indicators of Compromise

  • [Domain] southfirstarea[.]com, peak-pjv[.]com, and other 404 TDS domains – 404 TDS infrastructure used to filter traffic
  • [IP Address] 178.20.45[.]197, 185.180.199[.]229 – TDS hosting and redirection
  • [SHA256] d934d109f5b446febf6aa6a675e9bcc41fade563e7998788824f56b3cc16d1ed, 29e447a6121dd2b1d1221821bd6c4b0e20c437c62264844e8bcbb9d4be35f013 – JS/WasabiSeed and MSI components
  • [SHA256] 02049ab62c530a25f145c0a5c48e3932fa7412a037036a96d7198cc57cef1f40, 6e53a93fc2968d90891db6059bac49e975c09546e19a54f1f93fb01a21318fdc – Screenshotter MSI and lumina.exe
  • [File] ke.msi, OCDService.vbs, lumina.exe, app.js, index.js – WasabiSeed and Screenshotter components
  • [URL] hxxp[:]//109[.]107.173.72/1/ke.msi, hxxp[:]//109[.]107.173.72/%serial%/download?path=e – MSI download and payloads
  • [Domain] moosdies[.]top – Rhadamanthys C2
  • [File] Document_24_jan-3559116.js – JavaScript loader used in the chain

Read more: https://www.proofpoint.com/us/blog/threat-insight/screentime-sometimes-it-feels-like-somebodys-watching-me