logo

MONSOON – ANALYSIS OF AN APT CAMPAIGN

ID: 03f90602-4152-4645-8b27-8455ff7c0f6b

STIX ID: report--03f90602-4152-4645-8b27-8455ff7c0f6b

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2016-08-09

Last Modified Date: 2016-08-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Forcepoint Security Labs presents an in-depth analysis of the MONSOON APT campaign (Dec 2015–Jul 2016) that used topical lure documents and multiple weaponised exploits to deliver BADNEWS, TINYTYPHON, AutoIt backdoors and Unknown Logger; the malware used resilient C2 via RSS/GitHub/forums and exfiltrated sensitive government and military documents across South Asia, with extensive IOCs, exploited CVEs and infrastructure overlaps linking MONSOON to previously observed HANGOVER activity.