logo

APT-Q-27 Targeting Corporate Environments in Stealthy Attack Without Triggering Alerts

ID: 388ffc8d-6e1d-51b1-9098-0f64921d6ca7

STIX ID: report--388ffc8d-6e1d-51b1-9098-0f64921d6ca7

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-02-06

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**CyStack** reported a mid-January 2026 targeted, highly stealthy malware campaign against financial institutions attributed to APT-Q-27 (GoldenEyeDog); the intrusion began via a malicious Zendesk ticket link delivering a disguised .pif executable that used a timestamped signed certificate to bypass SmartScreen, then performed DLL sideloading (crashreport.dll) and in-memory execution from a deceptive Windows Update–like staging directory, enabling persistent C2 and modular payload delivery while avoiding typical endpoint detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.