Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor’s Repository

By Palo Alto Networks, Unit 42


In mid-July, Palo Alto Networks Unit 42 identified a small targeted phishing campaign aimed at a government organization. While tracking the activities of this campaign, we identified a repository of additional malware, including a web server that was used to host the payloads used for both this attack as well as others. We’ll discuss how we discovered it, as well as possible attribution towards the individual behind these attacks.

Topic Map