China-Based Red Lamassu Targets Telecoms Across Asia
ID: bd512e04-b046-56a4-9053-3dfbdf7fa8f2
STIX ID: report--bd512e04-b046-56a4-9053-3dfbdf7fa8f2
Feed Name: securityonline.info
PwC Threat Intelligence documents a sustained Red Lamassu (aka Calypso) cyber-espionage campaign targeting regional telecommunications in Kazakhstan, Afghanistan, and India; investigators found an open directory containing both Linux samples and a Windows backdoor named JFMBackdoor (delivered via DLL side-loading) capable of remote shell access, file operations, proxying, screenshot capture and self-removal, with forensic ties to a compromise of an Afghan telecom domain controller.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
