Squidoor: Suspected Chinese Threat Actor’s Backdoor Targets Global Organizations
ID: a677eae6-fc00-590e-b173-f59d5f8ba365
STIX ID: report--a677eae6-fc00-590e-b173-f59d5f8ba365
Feed Name: Palo Alto Networks Unit 42
Threat Score
This Unit 42 report analyzes CL-STA-0049, a suspected Chinese APT campaign using IIS exploits and web shells to deploy a multi-platform stealth backdoor called Squidoor (FinalDraft) across Southeast Asia and South America; Squidoor supports numerous covert C2 methods (including Outlook API, DNS and ICMP tunneling), performs in-memory code injection and lateral movement, and the report provides detailed TTPs, IOCs (file hashes, domains, IPs) and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
