216.73.216.6

UNC Cluster Targeting South Asian Countries

· Published 27/08/2025 16:22 · Modified 27/08/2025 19:44

Export JSON

Essential information

Published
27/08/2025 16:22
Modified
27/08/2025 19:44
Tags
2025-08-27 android malware credential-theft information stealer military targets phishing rafel rat remote access south asian apt
Related entities
2 techniques (mitre), 1 malware, 7 others

Description

A group has been consistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. The operation involves campaigns using military-themed lures to compromise phones of military personnel. The attackers employ various tactics, including PDF documents, fake login pages for government and military organizations, and malicious Android apps. The , based on the , steals information and provides . Victims are primarily from South Asian countries, with stolen data including SMS messages, contact lists, and documents. The operation also uses Windows malware with the same command and control infrastructure.

External references