#FlashCobra

Incident/Operation

2020-05-05 • Operation Flash Cobra

Operation FlashCobra is a Windows intrusion chain that begins with a malicious Office document using remote template injection to retrieve a second-stage macro document. The macro defines supporting functions, decodes embedded data, creates and checks files and directories, and loads a library for subsequent execution. The chain combines externally retrieved templates, macro-driven decoding, and local file operations to stage malicious code across multiple steps rather than executing the final payload directly from the initial document.

Tagged Reports

« Back