Cisco and Palo Alto researchers detailed multiple intrusion campaigns that relied on evasive malware to establish persistence and hide command-and-control traffic, including ObliqueRAT, GoldMax, NimzaLoader, and the SUNBURST backdoor tied to the SolarWinds Orion supply-chain compromise. In the SolarWinds intrusion, attackers distributed a trojanized, digitally signed Orion update that deployed SUNBURST, which masked its communications as legitimate Orion Improvement Program traffic and was later used to deliver follow-on payloads such as TEARDROP and customized Cobalt Strike BEACON implants.
Cisco Talos also reported that Transparent Tribe revived ObliqueRAT in campaigns aimed largely at organizations in South Asia, using malicious Office documents to retrieve payloads concealed in BMP image files hosted on hijacked websites. Researchers said newer ObliqueRAT variants added anti-analysis features, screenshot and webcam capture, removable-drive file theft, and updated persistence methods, while Cisco’s broader threat review noted that GoldMax used encrypted per-implant configuration and decoy traffic, and NimzaLoader used phishing emails, fake PDF-preview links, JSON-based communications, and process injection to deliver second-stage access.

Trace attribution and downstream blast radius.
10 events from the most recent confirmed update back to the earliest known activity.
Cisco Umbrella released a threat spotlight covering GoldMax, ObliqueRAT, and NimzaLoader, summarizing their malware behavior, targeting, infrastructure, and indicators of compromise.
Cisco Talos published details of a new ObliqueRAT campaign attributed to Transparent Tribe, highlighting steganography in BMP files, compromised websites for hosting payloads, and updated persistence and anti-analysis techniques.
Cisco Umbrella reported that TA800 had previously used BazaLoader before switching to NimzaLoader in February 2021 for phishing-delivered malware operations.
Talos said the ObliqueRAT campaign that began in April 2020 was still ongoing as of November 2020, continuing to use overlapping infrastructure with CrimsonRAT and possibly RevengeRAT.
Talos reported discovering ObliqueRAT versions 6.1, 6.3.2, 6.3.4, and 6.3.5 during this period, adding anti-analysis checks, removable-drive theft, screenshot and webcam capture, CSV targeting, and a changed mutex naming convention.
Cisco Talos said a new ObliqueRAT campaign attributed to Transparent Tribe started in April 2020, using malicious Office documents and compromised websites to deliver payloads hidden in BMP files.
The report states that FireEye released signatures and indicators to help defenders identify SolarStorm and related SUNBURST activity.
Unit 42 said SUNBURST delivered additional payloads including the TEARDROP memory-only dropper, which was used in at least one case to deploy a customized Cobalt Strike BEACON.
Unit 42 reported that attackers embedded the SUNBURST backdoor in a digitally signed, trojanized SolarWinds Orion update, with SolarWinds stating fewer than 18,000 customers ran the affected version out of more than 300,000 customers.
FireEye disclosed a breach and data exfiltration campaign it attributed to UNC2452, tied to a SolarWinds Orion supply-chain compromise affecting organizations worldwide.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 80 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
umbrella.cisco.com
Open sourceblog.talosintelligence.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.