216.73.216.6

Stately Taurus Activity in Southeast Asia Links to Bookworm Malware

· Published 20/02/2025 19:47 · Modified 21/02/2025 15:29

Export JSON

Essential information

Published
20/02/2025 19:47
Modified
21/02/2025 15:29
Tags
2025-02-20 asean bookworm dll sideloading infrastructure overlap modular malware pubload southeast asia toneshell
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 3 malware, 2 others

Description

Unit 42 researchers have discovered connections between Stately Taurus, a threat actor targeting countries, and the malware family. Analysis of infrastructure and code overlaps revealed links between recent Stately Taurus attacks and samples dating back to 2015. The group has been using both and malware in their operations. has undergone minimal changes since 2015, demonstrating its versatility and continued effectiveness. The malware's modular design allows for flexible packaging to meet operational needs. Stately Taurus is expected to continue developing and utilizing in future attacks targeting Southeast Asian organizations.

External references