Earth Wendigo Hackers Exploit Emails Via JS Backdoor
ID: 05f67288-0a12-5d84-bd7b-1acbf0a15380
STIX ID: report--05f67288-0a12-5d84-bd7b-1acbf0a15380
Feed Name: Cyble Blog
A threat actor named "Earth Wendigo" conducted a targeted campaign against Taiwanese government, research institutions, universities, and activists by injecting a JavaScript backdoor into a popular webmail system via XSS or by registering malicious Service Workers. The malicious scripts steal browser cookies and webmail session keys, exfiltrate emails and attachments to a WebSocket C2, propagate by appending payloads to outgoing emails, and are accompanied by Python shellcode loaders and Cobalt Strike-related components; the report includes extensive domain and hash IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
