logo

New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs

ID: 9e2b2f6f-f01b-5627-8109-db1f9566c5d4

STIX ID: report--9e2b2f6f-f01b-5627-8109-db1f9566c5d4

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-01-17

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft observed a targeted Mint Sandstorm (PHOSPHORUS/APT35) campaign since November 2023 that uses bespoke social engineering and compromised or spoofed accounts to lure academics and researchers into downloading malicious RAR/LNK payloads which retrieve multiple scripts and custom backdoors (MediaPl and MischiefTut). The report describes delivery and persistence techniques (double-extension .pdf.lnk invoking curl, registry Run keys, scheduled tasks), MediaPl’s C2 behavior and encryption, IoCs (domains and MediaPl.dll SHA-256), and provides detection, hunting queries, and mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.