Linux Malware DISGOMOJI Targets Indian Officials
ID: f557c037-f42e-541c-9da2-cd183da8837e
STIX ID: report--f557c037-f42e-541c-9da2-cd183da8837e
Feed Name: securityonline.info
Threat Score
Volexity reports a targeted cyber-espionage campaign (attributed to UTA0137) against Indian government entities running the BOSS Linux distribution, deploying a Golang ELF loader that installs DISGOMOJI — a Linux backdoor that uses Discord channels and emojis for C2, supports file exfiltration, persistence via cron, USB harvesting, and employs DirtyPipe for privilege escalation; the report includes TTPs, IoCs and YARA rules to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
