Uncovering TA397’s Targeted Malware Campaign Against Turkish Defense
Amber | Attack Report
Download PDFThreat actor TA397 targets organizations, especially in the Turkish defense sector, using spear-phishing emails with malicious LNK files disguised as infrastructure project documents. The attack chain installs WmRAT and MiyaRAT for espionage, leveraging scheduled tasks for stealthy payload delivery. This campaign underscores the need for robust email security and monitoring systems.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox