Pakistan-linked Malware Campaign Evolves to Target Windows, Android, and macOS
ID: 9441810d-e865-51b8-ac9c-bca76f5d408b
STIX ID: report--9441810d-e865-51b8-ac9c-bca76f5d408b
Feed Name: The Hacker News
Operation Celestial Force is a long-running (since at least 2018) campaign attributed to the Cosmic Leopard actor with ties to Pakistan, which leverages multi-platform malware—GravityRAT (Windows, Android, macOS), an Electron-based Windows loader called HeavyLift, and a management binary GravityAdmin—to target Indian subcontinent defense, government, and related technology entities via spear-phishing and social engineering; the malware harvests system and sensitive data and polls hard-coded C2 servers for follow-on payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
