logo

Operation SalmonSlalom: New Malware Campaign Targets Industrial Organizations in Asia-Pacific

ID: a1db1ceb-2845-5858-b2a0-12bdf683fac6

STIX ID: report--a1db1ceb-2845-5858-b2a0-12bdf683fac6

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: do son

...
...

Kaspersky ICS CERT details "Operation SalmonSlalom," a sophisticated, multi-stage campaign targeting industrial organizations across the Asia–Pacific that delivers the FatalRAT remote-access trojan via phishing (email, WeChat, Telegram). Attackers use packed first-stage loaders, retrieve dynamic payload URLs from Youdao Cloud Notes, leverage legitimate Chinese cloud/CDN services and DLL sideloading (abusing PureCodec) for persistence and evasion, and focus on sectors such as manufacturing, energy, healthcare, and logistics across multiple APAC countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.