Behind the Clouds: Attackers Targeting Governments in Southeast Asia Implement Novel Covert C2 Communication
ID: e9c07a9e-c94d-5595-836e-9f6ee9083c0d
STIX ID: report--e9c07a9e-c94d-5595-836e-9f6ee9083c0d
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 tracked CL-STA-1020, an APT campaign targeting Southeast Asian government entities that deployed a novel Windows backdoor called HazyBeacon which uses DLL sideloading for persistence and abuses AWS Lambda function URLs as a covert C2 channel; attackers collected trade-related documents and attempted exfiltration via Google Drive and Dropbox, and the report includes technical analysis, IoCs (SHA256 hashes), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
