HollowQuill is a threat actor using fake research invitations and Cobalt Strike to infiltrate defense networks.
Analyst brief
The threat actor known as HollowQuill is targeting the Baltic State Technical University, which is linked to Russia's defense and aerospace industries. The campaign uses weaponized decoy documents disguised as official research invitations to infiltrate academic, governmental, and defense networks. Key TTPs include a malicious RAR file delivering a .NET dropper, a Golang-based shellcode loader, and Cobalt Strike for final payload. Defenders should monitor for phishing emails with fake research invitations, suspicious RAR attachments, and Cobalt Strike C2 communication.
HollowQuill
unknown
SEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known institution for various defense, aerospace, and advanced engineering programs that contribute to Russia’s military-industrial complex. Tracked as Operation HollowQuill, the campaign leverages weaponized decoy documents masquerading as official research invitations to infiltrate academic, governmental, and defense-related networks. The threat entity delivers a malicious RAR file which contains a .NET malware dropper, which further drops other Golang based shellcode loader along with legitimate OneDrive application and a decoy-based PDF with a final Cobalt Strike payload.