Sindoor Dropper: New Phishing Campaign
Sept. 2, 2025, 9:33 a.m.
Description
A sophisticated phishing campaign targeting Indian organizations has been uncovered, utilizing spear-phishing techniques reminiscent of Operation Sindoor. The campaign employs a Linux-focused infection method using weaponized .desktop files, a tactic previously associated with APT36. When executed, these files initiate a complex, obfuscated chain that ultimately delivers a MeshAgent payload, granting the attacker full remote access to the compromised system. The campaign showcases an evolution in regional threat actor tactics, particularly in targeting Linux environments. By combining localized spear-phishing lures with advanced obfuscation techniques, the adversaries increase their chances of bypassing defenses and gaining footholds in sensitive networks. The attack chain involves multiple stages of encryption and decryption, anti-VM checks, and the use of legitimate remote administration tools to complicate detection and response efforts.
Tags
Date
- Created: Sept. 2, 2025, 8:34 a.m.
- Published: Sept. 2, 2025, 8:34 a.m.
- Modified: Sept. 2, 2025, 9:33 a.m.
Indicators
- ba5b485552ab775ce3116d9d5fa17f88452c1ae60118902e7f669fd6390eae97
- a6aa76cf3f25c768cc6ddcf32a86e5fcf4d8dd95298240c232942ce5e08709ec
- b46889ed27b69b94fb741b4d03be7c91986ac08269f9d7c37d1c13ea711f6389
- 9a1adb50bb08f5a28160802c8f315749b15c9009f25aa6718c7752471db3bb4b
- 9943bdf1b2a37434054b14a1a56a8e67aaa6a8b733ca785017d3ed8c1173ac59
- 6879a2b730e391964afe4dbbc29667844ba0c29239be5503b7c86e59e7052443
- 6b1420193a0ff96e3a19e887683535ab6654b2773a1899c2ab113739730924a1
- 38b6b93a536cbab5c289fe542656d8817d7c1217ad75c7f367b15c65d96a21d4
- 0f4ef1da435d5d64ccc21b4c2a6967b240c2928b297086878b3dcb3e9c87aa23
- 231957a5b5b834f88925a1922dba8b4238cf13b0e92c17851a83f40931f264c1
- 05b468fc24c93885cad40ff9ecb50594faa6c2c590e75c88a5e5f54a8b696ac8
- http://boss-servers.gov.in.indianbosssystems.ddns.net:443/agent.ashx
- indianbosssystems.ddns.net
- boss-servers.gov.in.indianbosssystems.ddns.net
Additional Informations
- Government
- British Indian Ocean Territory
- India