Update: Cyber Spies Digging For Clues On Iraq?
ID: 538a4352-2d41-5956-b840-29f214c0ee96
STIX ID: report--538a4352-2d41-5956-b840-29f214c0ee96
Feed Name: Security Ledger
CrowdStrike identified a multi-year, sophisticated espionage campaign by the APT dubbed DEEP PANDA targeting Washington D.C. think tanks and related organizations to collect policy-related documents on Iraq and the Middle East; attackers used SQL injection against public-facing infrastructure, PowerShell-based lateral movement and .NET payloads (Wafer and MadHatter RAT), with in-memory backdoors and file exfiltration observed, and CrowdStrike links the activity to a likely Chinese state-sponsored actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
