DONOT's Attack On Maritime & Defense Manufacturing
ID: b47c9f72-8541-595e-a6a8-16e6a9f3ac0b
STIX ID: report--b47c9f72-8541-595e-a6a8-16e6a9f3ac0b
Feed Name: Cyble Blog
This report describes a DONOT (APT‑C‑35) campaign that uses malicious .LNK files containing PowerShell to extract an encrypted lure RTF and stager DLL, establishes persistence via scheduled tasks invoking rundll32.exe, communicates with AES-encrypted C2 servers (with dynamically generated backup domains), and collects system information to guide payload delivery; the writeup includes technical indicators (hashes, domain, IP), TTP mapping to MITRE ATT&CK, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
