Babylon RAT Unleashed: Malaysian Politicians Under Cyber Siege
ID: 00dc1f74-d772-5705-8b46-e30816d59f05
STIX ID: report--00dc1f74-d772-5705-8b46-e30816d59f05
Feed Name: securityonline.info
A Cyble Research and Intelligence Lab investigation found a targeted cyber espionage campaign active since July 2023 that uses malicious ISO files to deploy the Babylon RAT against Malaysian political and government figures; the delivery uses shortcut-based PowerShell execution to launch a hidden executable named "controller.exe" while showing a decoy PDF, creates registry persistence, employs AES-256 encryption and a ~300MB overlay for evasion, and connects to C2 servers (149.28.19.207 and 64.176.65.152) over port 443 to exfiltrate data and enable remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
