SiestaGraph: New implant uncovered in ASEAN member foreign ministry
ID: 73bdca91-e641-522c-b405-9e6bbf2f9d2c
STIX ID: report--73bdca91-e641-522c-b405-9e6bbf2f9d2c
Feed Name: Elastic Security Labs
Elastic Security Labs documents an active, sophisticated intrusion (REF2924) against an ASEAN foreign ministry where adversaries exploited internet-connected Microsoft Exchange servers to execute malware, export and exfiltrate targeted mailboxes (24 accounts), deploy IIS webshells and custom backdoors (SiestaGraph, DoorMe), leverage a vulnerable kernel driver, and perform extensive internal reconnaissance; the report provides malware analysis, IOCs, MITRE ATT&CK mappings, and detection/hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
