DISGOMOJI Malware Used to Target Indian Government
ID: 9b706ba0-02f6-5acf-95ee-a52b5fe2d971
STIX ID: report--9b706ba0-02f6-5acf-95ee-a52b5fe2d971
Feed Name: Volexity Blog
Threat Score
Volexity describes a 2024 targeted cyber-espionage campaign by a suspected Pakistan-based actor (UTA0137) using a Golang Linux backdoor called DISGOMOJI that uses Discord emoji-based command-and-control to interact with victims, exfiltrate documents and browser data, and maintain persistence on BOSS Linux systems; the actor also leveraged the DirtyPipe (CVE-2022-0847) exploit for privilege escalation and employed open-source tunneling and staging services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
