Pakistani Hackers Use DISGOMOJI Malware in Indian Government Cyber Attacks
ID: 25e7e191-6529-528f-aafc-a13bf3bd4010
STIX ID: report--25e7e191-6529-528f-aafc-a13bf3bd4010
Feed Name: The Hacker News
Volexity reported that a suspected Pakistan-based actor, tracked as UTA0137, ran a 2024 cyber-espionage campaign against Indian government targets using a Golang Linux backdoor named DISGOMOJI — a custom fork of Discord-C2 that communicates via emojis for per-victim channels. Infection began with spear-phishing delivering a Golang ELF which staged a benign lure while fetching the DISGOMOJI payload; capabilities include command execution, screenshots, file upload/download, Firefox profile theft, persistence, anti-analysis measures, and use of tools and exploits (e.g., DirtyPipe) for lateral movement and privilege escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
