ModifiedElephant__2022__modified-elephant-apt.pdf
ID: 683e0a63-66f0-465b-aff1-76fdffe4f4e0
STIX ID: report--683e0a63-66f0-465b-aff1-76fdffe4f4e0
Threat Score
86/100
Uploaded: 2026-08-19
Published Date: 2022-02-09
Last Modified Date: 2022-02-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ModifiedElephant is a decade-long targeted surveillance and evidence-fabrication campaign in India described by SentinelLabs: attackers used spearphishing (malicious Office docs, executables, large RARs) to deploy commodity RATs (NetWire, DarkComet), brittle Visual Basic keyloggers, and an Android trojan to exfiltrate data and plant incriminating files; the report includes infrastructure and file IOCs, discusses overlaps with other actors and potential state-aligned motives, and links intrusions to real-world arrests.
