Babylon RAT Campaign Targets Malaysian Politicians
ID: 7ad2947b-2cd8-5470-86f7-4f52c6af907b
STIX ID: report--7ad2947b-2cd8-5470-86f7-4f52c6af907b
Feed Name: Cyble Blog
Threat Score
This report details a targeted campaign (active since July) using malicious ISO files that deploy a PowerShell-driven infection chain to install Babylon RAT on devices belonging to Malaysian political figures and government officials; it provides technical analysis of the wrapper and encrypted payload, C2 infrastructure (IPs and domains), MITRE technique mappings, IoCs (file hashes, LNK/PS1/EXE names, IPs, domains), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
