VICEROY_TIGER__2013__NS-Unveiling-an-Indian-Cyberattack-Infrastructure_FINAL_Web.pdf
ID: f56c1fb4-f4aa-490b-ba25-8640f32ef964
STIX ID: report--f56c1fb4-f4aa-490b-ba25-8640f32ef964
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2013-08-08
Last Modified Date: 2013-08-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation HangOver analyzes a multi-year Indian-origin cyberattack infrastructure used for surveillance and corporate espionage, detailing spear-phishing campaigns, CVE-2012-0158 RTF exploits, VB-based Smackdown downloaders, and HangOver/Hanove malware; it maps C2 domains, infrastructure, and domain registrations, and links the activity to real-world targets such as Telenor and other international entities, suggesting a state-sponsored threat actor conducting sustained campaigns.
