SilentSelfie: Uncovering a major watering hole campaign against Kurdish websites
ID: c20fea23-6331-51d2-abe0-efb4090a7d8a
STIX ID: report--c20fea23-6331-51d2-abe0-efb4090a7d8a
Feed Name: Sekoia.io Blog
Date Published: 2024-09-25
Date Updated: 2026-04-29
Author: Sekoia TDR, Felix Aimé and Maxime A.
Sekoia TDR uncovered a sustained watering‑hole campaign (first observed late 2022) compromising 25 Kurdish-linked sites with four JavaScript variants that exfiltrate location, WebRTC/local IPs, device/browser fingerprints, capture selfie images, and selectively redirect targets to install a malicious Android APK that beacons location and can exfiltrate contacts and files; the report includes technical analysis, IOCs (domains, IPs, APK hashes), YARA rules, and attribution hypotheses but finds no match to known intrusion sets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
