Operation ShadowCat: Stealthy RAT Targets Indian Politics
ID: 9bc6f922-429a-521b-8478-eb5f24e60186
STIX ID: report--9bc6f922-429a-521b-8478-eb5f24e60186
Feed Name: Cyble Blog
Threat Score
Operation ShadowCat is a sophisticated phishing campaign that uses a deceptive .LNK file to run embedded PowerShell which loads a .NET loader that retrieves a steganographically concealed GZip payload from PNGs; the payload is injected into powershell.exe via APC and executes a Go-based RAT providing extensive remote control, exfiltration, Active Directory/credential tooling, and ransomware staging—multiple IOCs, a YARA rule, and MITRE ATT&CK mappings are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
