CloudFall Campaign Targets Researchers and Scientists
ID: 20cd6afd-a717-5138-9738-5ac760d96da7
STIX ID: report--20cd6afd-a717-5138-9738-5ac760d96da7
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz documents a sophisticated, multi-stage targeted campaign (CloudFall) observed in August 2021 that used malicious Word documents and Cloudflare Workers to deploy persistent, obfuscated backdoors against researchers and conference invitees in Central Asia and Eastern Europe; the report details macro techniques, two attack variants, binary analysis, sandbox evasion, C2 infrastructure, IOCs (hashes, domains, SSL thumbprints), and assesses overlap with the CloudAtlas APT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
