logo

Pakistani Hackers Use DISGOMOJI Malware in Indian Government Cyber Attacks

ID: 25e7e191-6529-528f-aafc-a13bf3bd4010

STIX ID: report--25e7e191-6529-528f-aafc-a13bf3bd4010

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-06-15

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Volexity reported that a suspected Pakistan-based actor, tracked as UTA0137, ran a 2024 cyber-espionage campaign against Indian government targets using a Golang Linux backdoor named DISGOMOJI — a custom fork of Discord-C2 that communicates via emojis for per-victim channels. Infection began with spear-phishing delivering a Golang ELF which staged a benign lure while fetching the DISGOMOJI payload; capabilities include command execution, screenshots, file upload/download, Firefox profile theft, persistence, anti-analysis measures, and use of tools and exploits (e.g., DirtyPipe) for lateral movement and privilege escalation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.