MONSOON – ANALYSIS OF AN APT CAMPAIGN
ID: 03f90602-4152-4645-8b27-8455ff7c0f6b
STIX ID: report--03f90602-4152-4645-8b27-8455ff7c0f6b
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2016-08-09
Last Modified Date: 2016-08-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Forcepoint Security Labs presents an in-depth analysis of the MONSOON APT campaign (Dec 2015–Jul 2016) that used topical lure documents and multiple weaponised exploits to deliver BADNEWS, TINYTYPHON, AutoIt backdoors and Unknown Logger; the malware used resilient C2 via RSS/GitHub/forums and exfiltrated sensitive government and military documents across South Asia, with extensive IOCs, exploited CVEs and infrastructure overlaps linking MONSOON to previously observed HANGOVER activity.
