APT36 利用 Desktop 诱饵和 Poseidon 后门攻击印度基础设施
hunt.io | 博客 | #phishing | #india | #apt36 | #transparent-tribe | #poseidon-backdoor | #desktop-files
摘要
APT36(Transparent Tribe)将攻击范围从军事目标扩展至印度铁路、油气设施与外交部:.desktop 文件伪装成 PDF 投递载荷,借 cron 建立持久化,并使用基于 Mythic 框架的 Go 语言 Poseidon 后门;另发现 100+ 个仿冒印度政府机构的钓鱼域名。
- 发布时间
- 收录时间
Skip to content