CamelClone Uses Public File-Sharing Sites in Government Cyberattacks
ID: 182f7950-51f8-57eb-bafd-3029ea066d53
STIX ID: report--182f7950-51f8-57eb-bafd-3029ea066d53
Feed Name: GBHackers
Operation CamelClone is a targeted cyber‑espionage campaign that distributes spear‑phishing ZIP archives with LNK shortcuts to execute a JavaScript loader (HOPPINGANT) which fetches further components from filebulldogs.com; the operation uses a legitimate Rclone binary to collect and exfiltrate document files and Telegram Desktop session data to MEGA (credentials XOR‑encoded). Targets include government, defense, diplomatic, and energy organizations in Algeria, Mongolia, Ukraine, and Kuwait, and the report includes multiple SHA‑256 IOCs and filenames.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
