Stealth Falcon preying over Middle Eastern skies with Deadglyph
ID: 4265aaee-d37c-56ad-84fb-53d97d78c713
STIX ID: report--4265aaee-d37c-56ad-84fb-53d97d78c713
Feed Name: WeLiveSecurity (ESET Research)
ESET Research discovered and analyzed Deadglyph, a sophisticated, modular backdoor attributed to the Stealth Falcon APT targeting a Middle Eastern government; the report describes a multistage registry-based loader, a native x64 Executor that hosts a .NET Orchestrator, module-based command delivery from C2, multiple evasion techniques (machine-specific keys, obfuscation, AMSI avoidance), associated multistage shellcode downloader, IoCs (file hashes, certificates, C2 addresses), and mapped MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
