Phishing Espionage Attack Targets US-Taiwan Defense Conference
ID: 9581a3be-9894-5149-992c-41ba8aa26d73
STIX ID: report--9581a3be-9894-5149-992c-41ba8aa26d73
Feed Name: Dark Reading
A spear-phishing email impersonating a conference registrant delivered a ZIP file with a malicious Windows LNK shortcut intended to persist via the startup folder and launch in-memory payloads that could steal data and exfiltrate it via blended web traffic; the US-Taiwan Business Council detected the file, submitted it to VirusTotal, and deleted it without compromise. Cyble analysis could not attribute the attack to a specific actor but flagged the technique as a stealthy, fileless infostealer consistent with long-term surveillance operations targeting US–Taiwan defense cooperation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
