How Adversaries Use Spear Phishing to Target Engineering Staff
ID: 0e15d042-29f1-5746-a52d-01a14fc74df6
STIX ID: report--0e15d042-29f1-5746-a52d-01a14fc74df6
Feed Name: Dragos Blog
Engineering-focused spear-phishing and watering-hole campaigns tracked by Dragos target engineering and operations personnel to steal credentials and gain access to IT/OT environments. The report details multiple threat groups (TALONITE, ALLANITE, STIBNITE, DYMALLOY), malware components (LookBack, FlowCloud), and TTPs including malicious documents/macros, SMB/NTLM credential harvesting, watering-hole compromises, typo‑squatted and Punycode domains; it concludes with mitigations such as targeted phishing exercises, blocking outbound SMB, and hunting for 'xn--' domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
