A close look at the advanced techniques used in a Malaysian-focused APT campaign
ID: 538d5806-aeb5-5275-9906-b53a920e73de
STIX ID: report--538d5806-aeb5-5275-9906-b53a920e73de
Feed Name: Elastic Security Labs
Elastic Security Intelligence & Analytics Team details a targeted espionage campaign likely linked to APT40 (Leviathan) that used a malicious Word remote template and VBA macros to drop two small DLLs which download and execute a vulnerable LogiMailApp/LogiMail.dll pair via DLL side-loading; the DLL then stages and decrypts an in-memory second-stage backdoor with dynamic DNS C2. The report provides behavioral analysis, file/registry/URL/IP/hashes IOCs, a YARA rule, and assesses moderate confidence in attribution while highlighting techniques (template injection, macro execution, DLL search-order hijacking, in-memory execution) and persistence and exfiltration capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
