Afghan Government Compromise: Browser Beware
ID: 75a2eeed-0b97-5e35-9680-2f53bbcff596
STIX ID: report--75a2eeed-0b97-5e35-9680-2f53bbcff596
Feed Name: Volexity Blog
The report documents a strategic web compromise of the Afghan government CDN (cdn.afghanistan.af) in which attackers appended obfuscated JavaScript (using Dean Edwards Packer/base62) to jquery-1.4.2.min.js to perform a document.write that loads additional malicious JavaScript from 176.58.101.24 (Linode). The compromise affected multiple government websites, appears selectively targeted (whitelisting observed), and is attributed to APT-like actors; network indicators and ASN information are provided for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
