logo

Caramel_Tsunami__2021__Strategic_web_compromises_in_the_Middle_East_with_a_pinch_of_Candiru_WeLiveSecurity.pdf

ID: c0318474-1ff9-4cf7-87c2-b471edf055d2

STIX ID: report--c0318474-1ff9-4cf7-87c2-b471edf055d2

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2021-11-17

Last Modified Date: 2021-11-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET documents two waves of targeted watering-hole compromises affecting high-profile Middle Eastern sites (notably Yemen and related organizations) where attacker-controlled domains injected fingerprinting JavaScript to identify Windows/macOS browser visitors and likely redirect select targets to browser exploits; the report provides technical artifacts, many C2 domains/IPs and malware/document IoCs, links to Candiru and Karkadann, and MITRE ATT&CK mappings.