Uploaded August 2025 | Updated September 2026, 1 hour ago
Sathwik Ram Prakki (Quick Heal, IN), Subhajeet Singha (Quick Heal, IN)
Sathwik Ram Prakki works as Senior Security Researcher at Seqrite Labs, Quick Heal. His areas of research are threat intelligence, APT hunting, delving into dark web and malware analysis. With a background in offensive security and knowledge of OS internals, he is keen on enhancing detections and infrastructure for threat hunting and CTI. Starting his cybersecurity career at C-DAC, under the Ministry of Electronics & IT in India, Sathwik has shared insights on APTs, ransomware and malware ecosystems at conferences such as AVAR, Botconf, c0c0n, and Virus Bulletin.
Subhajeet is working as a Security Researcher in Security Labs at Quick Heal. His areas of focus are threat intelligence, research along with reverse engineering to improve detection capabilities and to aid in further research.
--
A new campaign targeting various industries such as the Defense Sector in Pakistan and predominantly researchers from Hong Kong has been uncovered. Tracked as Operation Cobalt Whisper, the entire campaign heavily leverages the use of a post-exploitation tool Cobalt Strike, which is deployed using obfuscated VBScript. A total of 20 infection chains have been identified along with additional individual samples, where 18 of them targeted Hong Kong and have two targeted Pakistan where over 30 decoy files have been identified.In this talk, we will explore the technical details of one of the campaigns we encountered during our initial analysis and examine the various stages of the infection chain, starting with a deep dive into the decoy documents. We will then investigate the common Tactics, Techniques, and Procedures (TTPs), such as the use of malicious VBScript and LNK payloads employed by this threat actor across most campaigns. These methods facilitate the in-memory execution of the Cobalt Strike implant, which is delivered alongside these lures in an archive file. At the end, we will explore hunting of its infrastructure that leads us to multiple host-headers of Cobalt Strike beaconing from Chinese ASN and correlation with Bitter APT.
Sathwik Ram Prakki (Quick Heal, IN), Subhajeet Singha (Quick Heal, IN)
Sathwik Ram Prakki works as Senior Security Researcher at Seqrite Labs, Quick Heal. His areas of research are threat intelligence, APT hunting, delving into dark web and malware analysis. With a background in offensive security and knowledge of OS internals, he is keen on enhancing detections and infrastructure for threat hunting and CTI. Starting his cybersecurity career at C-DAC, under the Ministry of Electronics & IT in India, Sathwik has shared insights on APTs, ransomware and malware ecosystems at conferences such as AVAR, Botconf, c0c0n, and Virus Bulletin.
Subhajeet is working as a Security Researcher in Security Labs at Quick Heal. His areas of focus are threat intelligence, research along with reverse engineering to improve detection capabilities and to aid in further research.
--
A new campaign targeting various industries such as the Defense Sector in Pakistan and predominantly researchers from Hong Kong has been uncovered. Tracked as Operation Cobalt Whisper, the entire campaign heavily leverages the use of a post-exploitation tool Cobalt Strike, which is deployed using obfuscated VBScript. A total of 20 infection chains have been identified along with additional individual samples, where 18 of them targeted Hong Kong and have two targeted Pakistan where over 30 decoy files have been identified.In this talk, we will explore the technical details of one of the campaigns we encountered during our initial analysis and examine the various stages of the infection chain, starting with a deep dive into the decoy documents. We will then investigate the common Tactics, Techniques, and Procedures (TTPs), such as the use of malicious VBScript and LNK payloads employed by this threat actor across most campaigns. These methods facilitate the in-memory execution of the Cobalt Strike implant, which is delivered alongside these lures in an archive file. At the end, we will explore hunting of its infrastructure that leads us to multiple host-headers of Cobalt Strike beaconing from Chinese ASN and correlation with Bitter APT.










