Operation Jacana: Foundling hobbits in Guyana
ID: 4267be10-fa5d-5439-9117-31b6c890db2d
STIX ID: report--4267be10-fa5d-5439-9117-31b6c890db2d
Feed Name: WeLiveSecurity (ESET Research)
ESET details Operation Jacana, a targeted spearphishing campaign against a Guyanese government entity that delivered a novel C++ backdoor dubbed DinodasRAT (TEA-encrypted communications and screenshot/clipboard exfiltration) alongside a Korplug/PlugX variant; the report includes behavior analysis, supported commands, lateral movement and credential-dumping activity, IoCs (hashes, IPs, domains), and MITRE ATT&CK mappings, with medium confidence attribution to a China-aligned actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
