Operation SalmonSlalom: New Malware Campaign Targets Industrial Organizations in Asia-Pacific
ID: a1db1ceb-2845-5858-b2a0-12bdf683fac6
STIX ID: report--a1db1ceb-2845-5858-b2a0-12bdf683fac6
Feed Name: securityonline.info
Kaspersky ICS CERT details "Operation SalmonSlalom," a sophisticated, multi-stage campaign targeting industrial organizations across the Asia–Pacific that delivers the FatalRAT remote-access trojan via phishing (email, WeChat, Telegram). Attackers use packed first-stage loaders, retrieve dynamic payload URLs from Youdao Cloud Notes, leverage legitimate Chinese cloud/CDN services and DLL sideloading (abusing PureCodec) for persistence and evasion, and focus on sectors such as manufacturing, energy, healthcare, and logistics across multiple APAC countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
