logo

Attack on Indian Government, Financial Institutions

ID: 07338de3-108b-5b69-8e40-c0491f8709ad

STIX ID: report--07338de3-108b-5b69-8e40-c0491f8709ad

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents a targeted April 2020 phishing campaign against Indian government and banking organisations that delivered an HTA-based JsOutProx RAT and an obfuscated Java backdoor via malicious archive attachments; the report includes static and dynamic technical analysis, persistence and C2 behavior, plugin capabilities (file manager, screen capture, command execution), MITRE ATT&CK mapping, and IOCs (MD5 hashes and DDNS C2 domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.