Pakistani Hacking Team 'Celestial Force' Spies on Indian Gov't, Defense
ID: 23c7a2ef-e165-54e2-a55e-9a65b0ad541b
STIX ID: report--23c7a2ef-e165-54e2-a55e-9a65b0ad541b
Feed Name: Dark Reading
Cisco Talos attributes a persistent espionage campaign named Operation Celestial Force to a Pakistan-based APT called Cosmic Leopard, active since 2016 and targeting Indian government, defense, and related technology organizations using multi-platform malware (GravityRAT on Android and Mac/Windows components, and the HeavyLift loader). Attackers rely on spear-phishing and social-media engagement to deliver malicious apps or lure victims into uploading data to attacker-controlled cloud storage; recommended mitigations include using official app stores for Android and applying layered visibility and endpoint defenses on Windows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
