Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Gartner® Report: Strategic Roadmap for CTEM
Learn More
New Integration Partnership with WIZ!
Learn More
Threat Exposure Validation Impact Report 2025
Learn More

SiestaGraph And DoorMe Backdoors Used To Target ASEAN Member Foreign Ministry

December 21, 2022

Multiple threat actors are suspected to be behind attacks focused on the Foreign Affairs office of an ASEAN member. The adversaries likely took advantage of a flaw in an Internet facing Microsoft Exchange server for initial access. The DoorMe and SiestaGraph backdoors along with a Cobalt Strike beacon and multiple Windows binaries were used for lateral movement, exfiltrate sensitive data, and perform reconnaissance.