logo

A close look at the advanced techniques used in a Malaysian-focused APT campaign

ID: 538d5806-aeb5-5275-9906-b53a920e73de

STIX ID: report--538d5806-aeb5-5275-9906-b53a920e73de

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2022-06-22

Date Updated: 2026-04-27

...
...

Elastic Security Intelligence & Analytics Team details a targeted espionage campaign likely linked to APT40 (Leviathan) that used a malicious Word remote template and VBA macros to drop two small DLLs which download and execute a vulnerable LogiMailApp/LogiMail.dll pair via DLL side-loading; the DLL then stages and decrypts an in-memory second-stage backdoor with dynamic DNS C2. The report provides behavioral analysis, file/registry/URL/IP/hashes IOCs, a YARA rule, and assesses moderate confidence in attribution while highlighting techniques (template injection, macro execution, DLL search-order hijacking, in-memory execution) and persistence and exfiltration capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.