logo

Update: Cyber Spies Digging For Clues On Iraq?

ID: 538a4352-2d41-5956-b840-29f214c0ee96

STIX ID: report--538a4352-2d41-5956-b840-29f214c0ee96

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2014-07-08

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

CrowdStrike identified a multi-year, sophisticated espionage campaign by the APT dubbed DEEP PANDA targeting Washington D.C. think tanks and related organizations to collect policy-related documents on Iraq and the Middle East; attackers used SQL injection against public-facing infrastructure, PowerShell-based lateral movement and .NET payloads (Wafer and MadHatter RAT), with in-memory backdoors and file exfiltration observed, and CrowdStrike links the activity to a likely Chinese state-sponsored actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.