WarHawk: New APT backdoor from SideWinder
ID: 27940a0c-bbf9-503f-a6e1-daf93c02a753
STIX ID: report--27940a0c-bbf9-503f-a6e1-daf93c02a753
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz discovered and analyzed 'WarHawk', a new backdoor used by the SideWinder APT to target Pakistan via malicious ISO files containing LNK shortcuts; WarHawk implements four modules (download & execute, command execution, file manager info exfil, uploadFromC2), delivers Cobalt Strike loaders that use KernelCallbackTable process injection and a Pakistan Standard Time check to restrict execution, and communicates with C2 infrastructure (notably 146.190.235.137 and domains mimicking Pakistani agencies); the report includes technical behavioral analysis, stage-2 payload details, MITRE ATT&CK mappings, and IoCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
