Shadow Vector targets Colombian users via privilege escalation and court-themed SVG decoys
ID: 05defb82-6379-5892-88e4-34f2edec88ef
STIX ID: report--05defb82-6379-5892-88e4-34f2edec88ef
Feed Name: TRU Security by Acronis
Threat Score
Acronis TRU documents the Shadow Vector campaign targeting users in Colombia via spear-phishing SVG lures that lead to multistage payloads (JS/VBS/PowerShell stages, password-protected ZIPs) delivering AsyncRAT and Remcos through DLL side-loading, vulnerable driver abuse, process hollowing, and a modular .NET in-memory loader; the report includes technical analysis, IOCs, a YARA rule, and notes on anti-analysis, persistence and credential/keylogger theft capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
