Hackers Use Rare Stealth Techniques to Down Asian Military, Gov't Orgs
ID: c6b2e306-d0e4-5804-8969-08f2e382f791
STIX ID: report--c6b2e306-d0e4-5804-8969-08f2e382f791
Feed Name: Dark Reading
Researchers observed a targeted campaign—linked to an actor with similarities to APT41—using two stealthy techniques (GrimResource, leveraging a six-year-old APDS XSS to execute JavaScript from MSC files, and AppDomainManager Injection to load malicious .NET DLLs) to drop Cobalt Strike via spearphishing ZIPs against Taiwanese government agencies, the Philippine military, and Vietnamese energy organizations; defenders are advised to emphasize email hygiene and pre-execution blocking controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
