Operation North Star: Behind The Scenes
ID: 01fa57f8-fdc7-547c-847d-e1da4039ff54
STIX ID: report--01fa57f8-fdc7-547c-847d-e1da4039ff54
Feed Name: McAfee Labs Blog
This report analyzes Operation North Star, an advanced, targeted espionage campaign that used weaponized DOTM templates and a multistage implant chain (including a newly identified second-stage called Torisma) delivered from compromised websites; the adversary maintained sophisticated backend infrastructure (obfuscated ASP/PHP code, webshells, allow/block IP lists) to selectively deploy implants to vetted targets (including defense contractors and ISP address ranges across India, Russia, Israel, Australia, and Finland) and to execute custom shellcode and monitoring on infected hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
