logo

Operation HollowQuill – Weaponized PDFs Deliver a Cobalt Strike Malware Into Gov & Military Networks

ID: 0844f99a-6ae8-5e25-80f3-ae34e55b81f6

STIX ID: report--0844f99a-6ae8-5e25-80f3-ae34e55b81f6

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

SEQRITE Labs uncovered 'Operation HollowQuill', a sophisticated cyber‑espionage campaign targeting Russian academic, government, and defense networks. Attackers distribute a malicious RAR containing a .NET dropper, a Go-based shellcode loader, a legitimate OneDrive binary used for process injection, and a decoy PDF; the payloads execute in memory (APC injection) and deploy Cobalt Strike beacons communicating with rotating C2 domains such as phpsymfony.com, while artifacts reveal anti-analysis techniques and exposed build identifiers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.