Operation Pawn Storm: Using Decoys to Evade Detection
ID: c2faf1d3-1dac-436b-819c-9944d0e4bbe0
STIX ID: report--c2faf1d3-1dac-436b-819c-9944d0e4bbe0
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2014-10-27
Last Modified Date: 2014-10-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Pawn Storm is a Trend Micro investigation into a persistent, multi-year APT campaign that targeted military, diplomatic, and defense contractor personnel across multiple countries using spear-phishing with weaponized attachments (exploiting CVE-2012-0158, CVE-2010-3333), malicious/typosquatted domains and OWA-focused JavaScript phishing, and multistage SEDNIT/Sofacy malware chains (downloaders, keyloggers) to exfiltrate credentials and sensitive data; the report includes case studies, IOCs (file hashes, IPs, domains), and mitigation recommendations.
