Operation RusticWeb targets Indian Govt: From Rust-based malware to Web-service exfiltration
ID: b7626bab-c4aa-5204-8e90-1b6c49f4a117
STIX ID: report--b7626bab-c4aa-5204-8e90-1b6c49f4a117
Feed Name: Seqrite Blog
SEQRITE Labs describes Operation RusticWeb, a spear-phishing campaign active since October 2023 targeting Indian government and defence-sector personnel using fake government-themed lures. Attackers deploy Rust-compiled binaries and encrypted PowerShell/maldocs to enumerate files and exfiltrate sensitive documents to public file-sharing services (OshiUpload) and cloud backends, using fake domains (e.g., awesscholarship.in, parichay.epar.in) for payload hosting; the report includes detailed infection chains, IOCs (MD5s, domains, URLs, PDBs, host paths), MITRE ATT&CK mappings, and detection identifiers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
