Caramel_Tsunami__2021__Strategic_web_compromises_in_the_Middle_East_with_a_pinch_of_Candiru_WeLiveSecurity.pdf
ID: c0318474-1ff9-4cf7-87c2-b471edf055d2
STIX ID: report--c0318474-1ff9-4cf7-87c2-b471edf055d2
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2021-11-17
Last Modified Date: 2021-11-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET documents two waves of targeted watering-hole compromises affecting high-profile Middle Eastern sites (notably Yemen and related organizations) where attacker-controlled domains injected fingerprinting JavaScript to identify Windows/macOS browser visitors and likely redirect select targets to browser exploits; the report provides technical artifacts, many C2 domains/IPs and malware/document IoCs, links to Candiru and Karkadann, and MITRE ATT&CK mappings.
