logo

VICEROY_TIGER__2013__NS-Unveiling-an-Indian-Cyberattack-Infrastructure_FINAL_Web.pdf

ID: f56c1fb4-f4aa-490b-ba25-8640f32ef964

STIX ID: report--f56c1fb4-f4aa-490b-ba25-8640f32ef964

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2013-08-08

Last Modified Date: 2013-08-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation HangOver analyzes a multi-year Indian-origin cyberattack infrastructure used for surveillance and corporate espionage, detailing spear-phishing campaigns, CVE-2012-0158 RTF exploits, VB-based Smackdown downloaders, and HangOver/Hanove malware; it maps C2 domains, infrastructure, and domain registrations, and links the activity to real-world targets such as Telenor and other international entities, suggesting a state-sponsored threat actor conducting sustained campaigns.