New DarkHotel APT attack chain identified
ID: 5ff2fd45-d785-5967-ba9b-f735d4320999
STIX ID: report--5ff2fd45-d785-5967-ba9b-f735d4320999
Feed Name: Zscaler Security Research Blog
This November 2021 report documents a DarkHotel APT campaign using a multi-layer malicious Office document (MD5 89ec1f32...) that drops a scriptlet (googleofficechk.sct) to install and execute two binaries (qq3104.exe, qq2688.exe). The chain includes PEB spoofing, UAC bypass, service-based persistence launching obfuscated PowerShell which loads an in-memory .NET downloader, and communicates with C2 domains (signing-config.com, svcstat.com, relay-server.com); the report includes C2/IP/domain analysis and IOCs, plus phishing domains targeting cryptocurrency wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
