Spy Campaign Spams Pro-Tibet Group With ExileRAT
#1
Quote:A cyber-espionage campaign has been spotted targeting recipients of a mailing list run by the Central Tibetan Administration (CTA).

India’s CTA is an organization officially representing the Tibetan government-in-exile. The territory of Tibet is administered by the People’s Republic of China – but the CTA considers that an illegitimate military occupation. The CTA instead believes that Tibet is a distinct independent nation.

Researchers with Cisco Talos recently discovered emails spamming subscribers on the CTA’s mailing list. The emails, which purport to be from the CTA, said they were commemorating the upcoming 60th anniversary of the Dalai Lama’s exile on March 31 with an attached Microsoft PowerPoint document titled “Tibet Was Never A Part of China.”

However, the attachment is actually a malicious PPSX file used as a dropper to allow an attacker to execute various JavaScript scripts and eventually download a payload onto the victims’ systems. That payload, a remote access trojan (RAT) called ExileRAT, scoops up their computer’s information.

SOURCE: https://threatpost.com/spy-spam-tibet-exilerat/141460/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Recuva 1.55.133
Recuva 1.55.133: ...harlan4096 — 06:17
AMD officially releases FSR 4.1 for Rade...
AMD FSR 4.1 now su...harlan4096 — 06:16
AMD Radeon Software Adrenalin 26.6.2 dri...
AMD Radeon Softwar...harlan4096 — 06:15
Valve leaks FSR 4.1 for RDNA 3 and RDNA ...
AMD planned RDNA 3...harlan4096 — 06:13
A VBScript campaign distributed through ...
In June 2026, we o...harlan4096 — 06:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>