Sponsor with batch-filed whiskers: Ballistic Bobcat’s scan and strike backdoor
ID: 033dbd95-68e3-5565-a8ec-ac227e2cb3f1
STIX ID: report--033dbd95-68e3-5565-a8ec-ac227e2cb3f1
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers uncovered a Ballistic Bobcat (APT35) campaign that exploited internet-facing Microsoft Exchange servers (CVE-2021-26855) to deploy a novel backdoor named Sponsor across at least 34 victims in Israel, Brazil, and the UAE; the report includes a full technical breakdown of Sponsor’s configuration, command-and-control protocol, persistence via Windows services, associated open-source tools, file and network IoCs, and MITRE ATT&CK mappings to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
