CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks
ID: 65fd4f1c-1703-55a7-872f-216a135a5d91
STIX ID: report--65fd4f1c-1703-55a7-872f-216a135a5d91
Feed Name: cybersecurityNews.com
Operation CamelClone is an active espionage campaign (late Feb–Mar 2026) targeting government, defense, and diplomatic entities in Algeria, Mongolia, Ukraine, and Kuwait. Attackers use spear-phishing ZIPs containing LNK shortcuts that execute PowerShell to fetch a JavaScript loader (HOPPINGANT) from filebulldogs.com; the chain deploys a portable Rclone (v1.70.3) and exfiltrates documents and Telegram session data to attacker-controlled MEGA accounts, leveraging public file hosting to blend malicious traffic with normal activity and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
