logo

SilentSelfie: Uncovering a major watering hole campaign against Kurdish websites

ID: c20fea23-6331-51d2-abe0-efb4090a7d8a

STIX ID: report--c20fea23-6331-51d2-abe0-efb4090a7d8a

Feed Name: Sekoia.io Blog

Threat Score
70/100

Date Published: 2024-09-25

Date Updated: 2026-04-29

Author: Sekoia TDR, Felix Aimé and Maxime A.

...
...

Sekoia TDR uncovered a sustained watering‑hole campaign (first observed late 2022) compromising 25 Kurdish-linked sites with four JavaScript variants that exfiltrate location, WebRTC/local IPs, device/browser fingerprints, capture selfie images, and selectively redirect targets to install a malicious Android APK that beacons location and can exfiltrate contacts and files; the report includes technical analysis, IOCs (domains, IPs, APK hashes), YARA rules, and attribution hypotheses but finds no match to known intrusion sets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.