logo

Pakistan-linked Malware Campaign Evolves to Target Windows, Android, and macOS

ID: 9441810d-e865-51b8-ac9c-bca76f5d408b

STIX ID: report--9441810d-e865-51b8-ac9c-bca76f5d408b

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-13

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Operation Celestial Force is a long-running (since at least 2018) campaign attributed to the Cosmic Leopard actor with ties to Pakistan, which leverages multi-platform malware—GravityRAT (Windows, Android, macOS), an Electron-based Windows loader called HeavyLift, and a management binary GravityAdmin—to target Indian subcontinent defense, government, and related technology entities via spear-phishing and social engineering; the malware harvests system and sensitive data and polls hard-coded C2 servers for follow-on payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.