Threat actor TA397 targets organizations, especially in the Turkish defense sector, using spear-phishing emails with malicious LNK files disguised as infrastructure project documents. The attack chain installs WmRAT and MiyaRAT for espionage, leveraging scheduled tasks for stealthy payload delivery. This campaign underscores the need for robust email security and monitoring systems.
Get through updates and upcoming events, and more directly in your inbox