logo

SiestaGraph: New implant uncovered in ASEAN member foreign ministry

ID: 73bdca91-e641-522c-b405-9e6bbf2f9d2c

STIX ID: report--73bdca91-e641-522c-b405-9e6bbf2f9d2c

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2022-12-16

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents an active, sophisticated intrusion (REF2924) against an ASEAN foreign ministry where adversaries exploited internet-connected Microsoft Exchange servers to execute malware, export and exfiltrate targeted mailboxes (24 accounts), deploy IIS webshells and custom backdoors (SiestaGraph, DoorMe), leverage a vulnerable kernel driver, and perform extensive internal reconnaissance; the report provides malware analysis, IOCs, MITRE ATT&CK mappings, and detection/hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.