TEMP.Metastrike
| Primary URL | Location | Industry | Undetermined |
Country
China
|
Undetermined
|
|---|
Profile
TEMP.Metastrike is a financially‑motivated cyber threat group that focuses on attacking financial institutions. The group conducts its operations primarily through spear phishing campaigns that masquerade as trusted financial partners or vendors. These campaigns deliver weaponized documents and binaries designed to infiltrate target networks. Once inside, the group deploys a range of malicious tools to establish footholds and move laterally.
TEMP.Metastrike is known for using obfuscated VBA scripts within malicious documents to evade detection. It also employs JavaScript‑based backdoors that achieve persistence via Windows registry modifications. Network traffic generated by the backdoors is encrypted with RC4 to conceal command‑and‑control communications. For reconnaissance, the group utilizes malware families such as CobInt and COOLPANTS to gather information about compromised systems. The identified command‑and‑control infrastructure includes domains like rietumu[.]me, which the group uses to issue instructions and exfiltrate data.
A notable incident attributed to TEMP.Metastrike occurred on 13 August 2018, when the group targeted financial organizations in Eastern Europe and Russia. During this campaign, the group successfully compromised a Russian bank and a Romanian financial institution. The attacks involved deploying tools capable of bypassing Windows defenses and facilitating the installation of ATM malware. These operations enabled the group to manipulate banking payment systems, resulting in significant financial losses for the victims.
TEMP.Metastrike is headquartered in China, as indicated by its known headquarters location. The group operates under the alias TEMP.Metastrike, which is used in threat intelligence reporting. No public information is available regarding the group's ownership, parent company, or subsidiary relationships. Consequently, the profile is limited to the observed activities, tactics, and geographic focus described in the available sources.
