logo

Operation Poisoned Helmand

ID: a3233c57-4650-4f6b-9c70-da949c8458ad

STIX ID: report--a3233c57-4650-4f6b-9c70-da949c8458ad

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2014-12-21

Last Modified Date: 2014-12-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Poisoned Helmand describes a watering-hole style attack in which Afghan government CDN resources were compromised to deliver a malicious JavaScript drive-by that loads a Java applet and a Windows payload, leveraging a compromised CDN to reach visitors of multiple government sites and linking to C2 infrastructure; the report cites related campaigns and emphasizes defense considerations such as Content Security Policy.