Threat intelligence
- First seen
- 2023-01-01 00:00:00
- Motivation
- Information theft and espionage
- TLP
- WHITE
(Knownsec 404) Recently, in the course of daily APT tracking,the Knownsec 404 Advanced Threat Intelligence team discovered an attack campaign by the APT-K-47 organization using the topic of “Hajj”, and the attackers used a CHM file to execute a malicious payload in the same directory. The final payload is relatively simple, supporting only the cmd shell, and is implemented using asynchronous programming, which is very similar to the “Asynshell” that was used by the organization several times during Our team’s tracking cycle from 2023 to the first half of 2024. Based on our tracking observations, the previously captured Asynshell has been updated in several versions, and based on the logic and functionality of the code, we have reason to suspect that this sample is an upgraded version of Asynshell.
Coverage 2
threat-intel
Chinese and Indian-aligned threat actors have been conducting sustained cyber espionage campaigns targeting Pakistani law enforcement organizations, including the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad…

threat-intel
Separate hacking campaigns, linked to China and India, targeted the same Pakistani police force – specifically the Balochistan Police – over a two-year period. These campaigns aimed to access sensitive data including cri…
