logo

Operation ShadowCat: Stealthy RAT Targets Indian Politics

ID: 9bc6f922-429a-521b-8478-eb5f24e60186

STIX ID: report--9bc6f922-429a-521b-8478-eb5f24e60186

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

Operation ShadowCat is a sophisticated phishing campaign that uses a deceptive .LNK file to run embedded PowerShell which loads a .NET loader that retrieves a steganographically concealed GZip payload from PNGs; the payload is injected into powershell.exe via APC and executes a Go-based RAT providing extensive remote control, exfiltration, Active Directory/credential tooling, and ransomware staging—multiple IOCs, a YARA rule, and MITRE ATT&CK mappings are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.