logo

Sindoor Dropper: New Phishing Campaign

ID: b0e4b3db-7deb-508b-ad1e-d98cae80ee7c

STIX ID: report--b0e4b3db-7deb-508b-ad1e-d98cae80ee7c

Feed Name: Nextron Systems

Threat Score
80/100

Date Published: 2025-08-29

Date Updated: 2026-04-28

Author: Pierre-Henri Pezier

...
...

This report analyzes a targeted spear‑phishing campaign (Sindoor) against Indian organizations that abuses Linux .desktop files to run an obfuscated multi-stage dropper chain (packed Go binaries with UPX, ELF magic stripping/restoration, AES/DES decryption stages and anti‑VM checks) and ultimately installs a MeshAgent remote‑access payload connecting to a documented C2 (wss://...indianbosssystems.ddns.net). The report provides full technical breakdowns, file hashes, YARA rules, decoded module routines, and recommended detection/mitigation artifacts, and links the tradecraft to APT36.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.