Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
ID: f45c5fb8-cf02-5a2d-b4cf-debc820ee214
STIX ID: report--f45c5fb8-cf02-5a2d-b4cf-debc820ee214
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 links the Stately Taurus APT to the Bookworm malware family and documents regional campaigns against ASEAN government entities, detailing loader and execution techniques (DLL sideloading, UUID-based shellcode executed via legitimate API callbacks), module evolution, and providing extensive IOCs (file hashes, domains, IPs) and related archives tied to C2 infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
