Shadow Vector targets Colombian users via privilege escalation and court-themed SVG decoys
ID: 4e7442f0-8797-5678-9aa0-4795b2c61d6f
STIX ID: report--4e7442f0-8797-5678-9aa0-4795b2c61d6f
Feed Name: TRU Security by Acronis
Threat Score
Shadow Vector is an active, regionally focused malware campaign targeting users in Colombia via malicious SVG attachments and public-hosted stagers; it delivers multistage payloads (AsyncRAT, RemcosRAT and memory-resident .NET loaders) using DLL side-loading, vulnerable kernel drivers for escalation, UAC bypasses, process injection and in-memory execution, enabling credential theft, keylogging and full remote access while leaving minimal disk artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
