logo

Stately Taurus Activity in Southeast Asia Links to Bookworm Malware

ID: f45c5fb8-cf02-5a2d-b4cf-debc820ee214

STIX ID: report--f45c5fb8-cf02-5a2d-b4cf-debc820ee214

Feed Name: Palo Alto Networks Unit 42

Threat Score
92/100

Date Published: 2025-02-20

Date Updated: 2026-04-28

Author: Robert Falcone

...
...

Unit 42 links the Stately Taurus APT to the Bookworm malware family and documents regional campaigns against ASEAN government entities, detailing loader and execution techniques (DLL sideloading, UUID-based shellcode executed via legitimate API callbacks), module evolution, and providing extensive IOCs (file hashes, domains, IPs) and related archives tied to C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.