Uncovering TA397’s Targeted Malware Campaign Against Turkish Defense

Amber | Attack Report
Download PDF

Threat actor TA397 targets organizations, especially in the Turkish defense sector, using spear-phishing emails with malicious LNK files disguised as infrastructure project documents. The attack chain installs WmRAT and MiyaRAT for espionage, leveraging scheduled tasks for stealthy payload delivery. This campaign underscores the need for robust email security and monitoring systems.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox