Operation Dragon Whistle Targets Changzhou University With Malicious LNK Files
ID: dcafa2b4-c0b7-5285-8a3f-206ab9274e47
STIX ID: report--dcafa2b4-c0b7-5285-8a3f-206ab9274e47
Feed Name: Cyber Press
Threat Score
A targeted phishing campaign against PSCA/PPIC3 in Pakistan used spear-phishing attachments (a macro-laden Word doc and a fake Adobe PDF) to deploy a VS Code Remote Tunnel backdoor via Microsoft device-code authentication and ClickOnce-delivered .NET payloads, exploited persistence via registry changes, and exfiltrated status codes to attacker-controlled Discord webhooks; several SHA-256 hashes are provided as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
