McAfee Defender’s Blog: Operation Dianxun
ID: 28f317ba-1309-5ee9-8400-9760a62b1763
STIX ID: report--28f317ba-1309-5ee9-8400-9760a62b1763
Feed Name: McAfee Labs Blog
Operation Diànxùn is an espionage campaign targeting telecommunications organizations (notably 5G-related) that uses a phishing website masquerading as a Huawei careers page to deliver a Flash-based downloader and a .NET payload which installs backdoors and Cobalt Strike beacons; the McAfee report documents TTPs, provides numerous IoCs (SHA256 hashes, domains, and an IP), and outlines detection and mitigation guidance across web gateways, endpoint protection, intrusion prevention, and EDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
