logo

Operation SkyCloak: Tor Campaign targets Military of Russia & Belarus

ID: db29821e-0d39-559c-a8bc-73c5f1c59683

STIX ID: report--db29821e-0d39-559c-a8bc-73c5f1c59683

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-10-31

Date Updated: 2026-04-30

Author: Sathwik Ram Prakki

...
...

SEQRITE Labs documents a targeted espionage campaign (SkyCloak) observed in Oct 2025 that lures Russian and Belarusian military personnel with decoy nomination/training PDFs; a spearphishing ZIP contains LNKs that trigger PowerShell to extract a multi-stage payload which installs a user-profile OpenSSH server and a Tor instance (with obfs4 bridges) to expose SSH/SMB/RDP as onion hidden services for covert remote access. The report details anti-analysis checks, scheduled-task persistence, SSH/Tor configurations, bundled legitimate OpenSSH/LibreSSL binaries, observable Tor bridge endpoints, and a set of IOCs and MITRE ATT&CK mappings; attribution is tentative and scored with low confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.