Covert Data Heist: APT36 Exploits ZIP Vulnerabilities in BOSS Linux Systems
ID: 1c9e7331-c58c-529b-83f9-95b4d47a2d1f
STIX ID: report--1c9e7331-c58c-529b-83f9-95b4d47a2d1f
Feed Name: Cyber Press
Threat Score
CYFIRMA identifies a sophisticated APT36 campaign targeting India’s defense sector by leveraging phishing ZIP attachments that drop a .desktop launcher which silently installs a Go-based ELF backdoor (BOSS.elf) on BOSS Linux systems; the malware performs system reconnaissance, captures screenshots, maintains persistent TCP C2 (notably 101.99.92.182:12520), and facilitates covert data exfiltration, with multiple IOCs and mitigation recommendations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
