Mongolia
MNG
Avast reported that Mongolian CA MonPass’ public web server was repeatedly breached and its official certificate client installer was backdoored with a Cobalt Strike-based RAT. The trojanized installer was available from February 8 to March 3, 2021, and investigators found eight webshells/backdoors on the compromised server.
Estimated severity
60 / 100
Source reliability
90 / 100
Approximate Date
03/03/2021
Targeted Company
MONPASS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Mongolia
MNG
No other affected countries reported
Target country
Mongolia
Affected countries
Impacted regions
Duration
24 days
Financial impact (USD M)
No information
Impact types
No information
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone