logo

CamelClone Uses Public File-Sharing Sites in Government Cyberattacks

ID: 182f7950-51f8-57eb-bafd-3029ea066d53

STIX ID: report--182f7950-51f8-57eb-bafd-3029ea066d53

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Operation CamelClone is a targeted cyber‑espionage campaign that distributes spear‑phishing ZIP archives with LNK shortcuts to execute a JavaScript loader (HOPPINGANT) which fetches further components from filebulldogs.com; the operation uses a legitimate Rclone binary to collect and exfiltrate document files and Telegram Desktop session data to MEGA (credentials XOR‑encoded). Targets include government, defense, diplomatic, and energy organizations in Algeria, Mongolia, Ukraine, and Kuwait, and the report includes multiple SHA‑256 IOCs and filenames.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.