Storm Cloud Unleashed: Tibetan Focus of Highly Targeted Fake Flash Campaign
ID: d83586d4-8086-5469-9d5d-e3ca05e98a54
STIX ID: report--d83586d4-8086-5469-9d5d-e3ca05e98a54
Feed Name: Volexity Blog
Volexity documents a targeted watering‑hole campaign attributed to a Chinese APT dubbed “Storm Cloud” that compromised over two dozen Tibetan websites beginning in 2018–2019, using obfuscated JavaScript to fingerprint visitors and show fake Adobe Flash update dialogs to socially engineer victims into installing Windows payloads; the report describes multiple delivered backdoors (PlugDat, Stitch, GOSLU, BrainDamage and simple downloaders), possible related Android RAT APKs, hosting and C2 infrastructure, and includes IoCs and helper scripts for analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
