logo

ExileRAT Malware Targets Tibetan Exile Government

ID: bf17c491-94cc-558a-86d2-8670727b0c18

STIX ID: report--bf17c491-94cc-558a-86d2-8670727b0c18

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2019-02-06

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Cisco Talos researchers discovered a politically motivated cyber-espionage campaign targeting the Central Tibetan Administration using a malicious PPSX file exploiting CVE-2017-0199 to deliver ExileRAT. The campaign's command-and-control infrastructure is linked to earlier LuckyCat Android and Windows RATs, and the malware provides extensive data-stealing and remote control capabilities consistent with espionage operations against Tibetan activists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.