Operation Poisoned Helmand
ID: a3233c57-4650-4f6b-9c70-da949c8458ad
STIX ID: report--a3233c57-4650-4f6b-9c70-da949c8458ad
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2014-12-21
Last Modified Date: 2014-12-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Poisoned Helmand describes a watering-hole style attack in which Afghan government CDN resources were compromised to deliver a malicious JavaScript drive-by that loads a Java applet and a Windows payload, leveraging a compromised CDN to reach visitors of multiple government sites and linking to C2 infrastructure; the report cites related campaigns and emphasizes defense considerations such as Content Security Policy.
