logo

DISGOMOJI Malware Used to Target Indian Government

ID: 9b706ba0-02f6-5acf-95ee-a52b5fe2d971

STIX ID: report--9b706ba0-02f6-5acf-95ee-a52b5fe2d971

Feed Name: Volexity Blog

Threat Score
88/100

Date Published: 2024-06-13

Date Updated: 2026-05-01

...
...

Volexity describes a 2024 targeted cyber-espionage campaign by a suspected Pakistan-based actor (UTA0137) using a Golang Linux backdoor called DISGOMOJI that uses Discord emoji-based command-and-control to interact with victims, exfiltrate documents and browser data, and maintain persistence on BOSS Linux systems; the actor also leveraged the DirtyPipe (CVE-2022-0847) exploit for privilege escalation and employed open-source tunneling and staging services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.