216.73.217.98

Operation Cobalt Whisper: Threat Actor Targets Multiple Industries Across Hong Kong and Pakistan

· Published 24/10/2024 12:59 · Modified 24/10/2024 14:21

Export JSON

Essential information

Published
24/10/2024 12:59
Modified
24/10/2024 14:21
Tags
2024-10-24 cobalt strike cyber espionage defense sector engineering hong kong lnk files pakistan vbscript
Related entities
7 techniques (mitre), 1 malware, 12 others

Description

A sophisticated campaign dubbed Operation Cobalt Whisper has been uncovered, targeting various industries in and . The threat actor focuses on the , researchers, and key entities in these regions, using tailored lures related to electrotechnical societies, energy infrastructure, and environmental . The campaign heavily relies on for post-exploitation, deploying it through obfuscated . The attack chain involves malicious , , and beacons. The operation has been active since May 2024, with over 20 infection chains identified. The threat actor's tactics suggest a methodical approach to cyber-espionage, aiming to compromise sensitive research and intellectual property.

External references