Attack on Indian Government, Financial Institutions
ID: 07338de3-108b-5b69-8e40-c0491f8709ad
STIX ID: report--07338de3-108b-5b69-8e40-c0491f8709ad
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ documents a targeted April 2020 phishing campaign against Indian government and banking organisations that delivered an HTA-based JsOutProx RAT and an obfuscated Java backdoor via malicious archive attachments; the report includes static and dynamic technical analysis, persistence and C2 behavior, plugin capabilities (file manager, screen capture, command execution), MITRE ATT&CK mapping, and IOCs (MD5 hashes and DDNS C2 domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
