KNOTWEED, an activity group attributed to Austrian private-sector offensive actor DSIRF, conducted targeted espionage campaigns against legal, financial, and NGO organizations in Europe and Central America. The group used zero-day vulnerabilities in Adobe Reader and Microsoft Windows to deploy DSIRF’s Subzero surveillance malware against selected victims in Europe and Latin America.
Subzero comprises the Jumplump persistence component and Corelump primary backdoor, providing credential theft, system-location discovery, host reconnaissance, and remote-access capabilities. Microsoft identified a VBA-based initial-access chain in the activity; Elastic reported its endpoint protection could detect and stop the associated shellcode-injection behavior, while noting it had not observed customer telemetry tied to the targeted campaign at the time of its assessment.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence Center disclosed KNOTWEED, an activity group attributed to DSIRF, which used Adobe Reader and Windows zero-day exploits to deploy Subzero spyware against legal, financial, and NGO targets in Europe and Latin America. Subzero used Jumplump for persistence and Corelump for host operations, including credential theft, reconnaissance, system-location collection, and remote access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.