Researchers documented targeted intrusion campaigns that used military and geopolitical decoy documents to compromise victims in South Asia and deploy Cobalt Strike. Cisco Talos reported that attackers distributed malicious Microsoft Office files posing as Indian Air Force and other government or military documents, with macros dropping a custom loader called IndigoDrop into the Windows Startup folder for persistence. IndigoDrop performed anti-infection checks, fetched Metasploit shellcode, and ultimately loaded an XOR-encoded Cobalt Strike beacon hidden in trojanized jQuery files, while related Python modules conducted reconnaissance and stole browser and Wi-Fi credentials.
A separate campaign analyzed by Zscaler used a Word document themed around the India-China border dispute to trigger a macro-delivered PowerShell chain that staged shellcode behind a fake GIF header and installed a Cobalt Strike beacon over HTTPS. The operators used fileless techniques, spoofed HTTP Host headers such as update.windows.microsoft.com, and in some variants injected an RSA-encrypted payload into notepad.exe; researchers also identified infrastructure including 47.240.73.77, 114.67.110.37, and 360doc.com-based command-and-control domains. Across both campaigns, the attackers relied on topical military lures, multi-stage loaders, and legitimate-looking web traffic to conceal remote access activity against likely government and defense-related targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By September 2019, the operators had productionized IndigoDrop-based samples and later shifted to Pastebin-hosted shellcode with additional anti-infection checks, indicating an evolution in delivery and staging tradecraft.
Cisco Talos traced the earliest observable variant of the campaign to April 2018, when malicious macros dropped a .crt file that was decoded with certutil into an SMB-based Cobalt Strike beacon.
Zscaler observed a related .NET payload variant that decrypted an RSA-encrypted payload and injected it into notepad.exe, while concluding it could not confidently attribute the campaign despite overlaps with OceanLotus and a watermark previously seen in Trickbot-related activity.
Zscaler ThreatLabZ analyzed a targeted attack using a malicious Word document themed around the India-China border dispute to launch a fileless infection chain that ultimately deployed a Cobalt Strike beacon over HTTPS.
Cisco Talos reported a targeted malware campaign using military-themed Office lures, likely aimed at military and government organizations in South Asia, to deliver IndigoDrop and customized Cobalt Strike beacons through a multistage infection chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcecobaltstrike.com
Open sourcecyber.wtf
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.