New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs
ID: 9e2b2f6f-f01b-5627-8109-db1f9566c5d4
STIX ID: report--9e2b2f6f-f01b-5627-8109-db1f9566c5d4
Feed Name: Microsoft Security
Microsoft observed a targeted Mint Sandstorm (PHOSPHORUS/APT35) campaign since November 2023 that uses bespoke social engineering and compromised or spoofed accounts to lure academics and researchers into downloading malicious RAR/LNK payloads which retrieve multiple scripts and custom backdoors (MediaPl and MischiefTut). The report describes delivery and persistence techniques (double-extension .pdf.lnk invoking curl, registry Run keys, scheduled tasks), MediaPl’s C2 behavior and encryption, IoCs (domains and MediaPl.dll SHA-256), and provides detection, hunting queries, and mitigations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
