Operation Dragon Whistle Uses Malicious LNK Files to Target Changzhou University
ID: e5d5dac4-f980-5bfa-a5bd-e12a22033200
STIX ID: report--e5d5dac4-f980-5bfa-a5bd-e12a22033200
Feed Name: cybersecurityNews.com
Threat Score
**Operation Dragon Whistle**: A coordinated phishing campaign targeting Pakistani government institutions that delivered a weaponized Word document (auto-running macro) and a deceptive PDF ClickOnce installer to download a malicious VS Code executable and establish VS Code remote tunnels for persistent remote access; report includes TTP details and multiple IoCs (file hashes and URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
