Operation HollowQuill: Malware delivered into Russian R&D Networks via Research Decoy PDFs
ID: 81defddc-7ede-5e51-b324-0960dc301d64
STIX ID: report--81defddc-7ede-5e51-b324-0960dc301d64
Feed Name: Seqrite Blog
Threat Score
**Operation HollowQuill**: SEQRITE Labs APT team uncovered a targeted campaign against Baltic State Technical University employing weaponized decoy PDFs inside a malicious RAR that drops a .NET dropper which installs a legitimate OneDrive binary, a Golang shellcode loader (APC injection into OneDrive.exe), and an in-memory Cobalt Strike beacon; the report provides technical stages, IOCs (MD5s, C2 phpsymfony.com), MITRE mappings, and hunting notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
