logo

Operation HollowQuill: Malware delivered into Russian R&D Networks via Research Decoy PDFs

ID: 81defddc-7ede-5e51-b324-0960dc301d64

STIX ID: report--81defddc-7ede-5e51-b324-0960dc301d64

Feed Name: Seqrite Blog

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-30

Author: Subhajeet Singha

...
...

**Operation HollowQuill**: SEQRITE Labs APT team uncovered a targeted campaign against Baltic State Technical University employing weaponized decoy PDFs inside a malicious RAR that drops a .NET dropper which installs a legitimate OneDrive binary, a Golang shellcode loader (APC injection into OneDrive.exe), and an in-memory Cobalt Strike beacon; the report provides technical stages, IOCs (MD5s, C2 phpsymfony.com), MITRE mappings, and hunting notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.