Threat Reports

Read other reports

Uncovering DNS Details on Operation Celestial Force

Operation Celestial Force is advanced persistent threat (APT) group Cosmic Leopard’s latest campaign targeting organizations primarily based in India.1 The threat actors used an Android and Windows malware combination to steal confidential data from targets.

A report of an in-depth investigation of Operation Celestial Force identified 19 domains as indicators of compromise (IoCs), which the WhoisXML API research team expanded to uncover other potentially connected artifacts.

Our in-depth analysis aided by DNS intelligence led to the discovery of:

  • Three email-connected domains
  • 15 IP addresses, all of which turned out to be malicious
  • 35 string-connected domains
  • 3,927 brand-containing domains, nine of which turned out to be associated with various threats

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://blog.talosintelligence.com/cosmic-leopard/

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.

Contact Us

White Paper Download

Please complete the form below to download the required file:

Your business email will be validated while the request is being processed. This may take time.