logo

CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks

ID: 65fd4f1c-1703-55a7-872f-216a135a5d91

STIX ID: report--65fd4f1c-1703-55a7-872f-216a135a5d91

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation CamelClone is an active espionage campaign (late Feb–Mar 2026) targeting government, defense, and diplomatic entities in Algeria, Mongolia, Ukraine, and Kuwait. Attackers use spear-phishing ZIPs containing LNK shortcuts that execute PowerShell to fetch a JavaScript loader (HOPPINGANT) from filebulldogs.com; the chain deploys a portable Rclone (v1.70.3) and exfiltrates documents and Telegram session data to attacker-controlled MEGA accounts, leveraging public file hosting to blend malicious traffic with normal activity and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.