logo

Earth Wendigo Hackers Exploit Emails Via JS Backdoor

ID: 05f67288-0a12-5d84-bd7b-1acbf0a15380

STIX ID: report--05f67288-0a12-5d84-bd7b-1acbf0a15380

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

A threat actor named "Earth Wendigo" conducted a targeted campaign against Taiwanese government, research institutions, universities, and activists by injecting a JavaScript backdoor into a popular webmail system via XSS or by registering malicious Service Workers. The malicious scripts steal browser cookies and webmail session keys, exfiltrate emails and attachments to a WebSocket C2, propagate by appending payloads to outgoing emails, and are accompanied by Python shellcode loaders and Cobalt Strike-related components; the report includes extensive domain and hash IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.