logo

Operation Jacana: Foundling hobbits in Guyana

ID: 4267be10-fa5d-5439-9117-31b6c890db2d

STIX ID: report--4267be10-fa5d-5439-9117-31b6c890db2d

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2023-10-05

Date Updated: 2026-05-01

...
...

ESET details Operation Jacana, a targeted spearphishing campaign against a Guyanese government entity that delivered a novel C++ backdoor dubbed DinodasRAT (TEA-encrypted communications and screenshot/clipboard exfiltration) alongside a Korplug/PlugX variant; the report includes behavior analysis, supported commands, lateral movement and credential-dumping activity, IoCs (hashes, IPs, domains), and MITRE ATT&CK mappings, with medium confidence attribution to a China-aligned actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.