216.73.216.6

Sindoor Dropper: New Phishing Campaign

· Published 02/09/2025 08:34 · Modified 02/09/2025 09:33

Export JSON

Essential information

Published
02/09/2025 08:34
Modified
02/09/2025 09:33
Tags
2025-09-02 apt36 linux meshagent obfuscation phishing sindoor spear-phishing
Related entities
14 observables, 1 intrusion sets (apt), 13 techniques (mitre), 1 malware, 3 others

Description

A sophisticated campaign targeting Indian organizations has been uncovered, utilizing techniques reminiscent of Operation . The campaign employs a -focused infection method using weaponized .desktop files, a tactic previously associated with . When executed, these files initiate a complex, obfuscated chain that ultimately delivers a payload, granting the attacker full remote access to the compromised system. The campaign showcases an evolution in regional threat actor tactics, particularly in targeting environments. By combining localized lures with advanced techniques, the adversaries increase their chances of bypassing defenses and gaining footholds in sensitive networks. The attack chain involves multiple stages of encryption and decryption, anti-VM checks, and the use of legitimate remote administration tools to complicate detection and response efforts.

External references