CL-STA-0048: An Espionage Operation Against High-Value Targets in South Asia
ID: bdc87905-8751-528c-a91f-bcd3f467504a
STIX ID: report--bdc87905-8751-528c-a91f-bcd3f467504a
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit42 describes CL-STA-0048, a sophisticated espionage campaign targeting high-value South Asian organizations (government and telecom) that exploited public-facing IIS, Apache Tomcat and MSSQL servers to gain access, deployed PlugX and Cobalt Strike (including DLL sideloading and privilege escalation), used a stealthy "Hex Staging" delivery method and DNS-based exfiltration to steal PII, and provides detailed mitigations and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
