logo

From South America to Southeast Asia: The Fragile Web of REF7707

ID: fa8ed59a-4603-5f78-b994-f08508a2ccec

STIX ID: report--fa8ed59a-4603-5f78-b994-f08508a2ccec

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2025-02-13

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents REF7707, a sophisticated intrusion campaign that targeted a South American foreign ministry and other victims using novel multi‑platform malware (FINALDRAFT with PATHLOADER and GUIDLOADER loaders). The attackers used LOLBin techniques (CDB.exe, certutil) for execution, harvested domain credentials and AD artifacts, maintained persistence via scheduled tasks, and blended C2 traffic through Microsoft Graph and various cloud/third‑party services; infrastructure pivots point to a Southeast Asia footprint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.