Analyzing Iranian Tradecraft: Leveraging Loader Scripts and Telegram for C2
ID: 6fc13811-f834-5c14-bceb-fb212f541d27
STIX ID: report--6fc13811-f834-5c14-bceb-fb212f541d27
Feed Name: Pulsedive Blog
Threat Score
This report analyzes a set of loader scripts and a payload linked to intrusions that use Telegram bots for command-and-control and exfiltration, describing PowerShell/VBScript loaders that retrieve a zip containing smqdservice.exe and Python modules; it includes sample hashes, IOCs, TTP mapping to MITRE ATT&CK, and recommended mitigations for detection and prevention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
