Targeted Attack Leverages India-China Border Dispute
ID: 3c35743f-cce3-5a38-889f-51906f5a5769
STIX ID: report--3c35743f-cce3-5a38-889f-51906f5a5769
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ identified a spearphishing campaign using a malicious Word attachment ('India-China border tensions.doc') that executes obfuscated macros and PowerShell to run DKMC-style, fileless shellcode which retrieves a GIF-embedded Cobalt Strike beacon over HTTPS (using fake Host headers); the report includes C2 IPs, beacon configs, hashes, and mapped MITRE ATT&CK TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
