logo

Shadow Vector targets Colombian users via privilege escalation and court-themed SVG decoys

ID: 4e7442f0-8797-5678-9aa0-4795b2c61d6f

STIX ID: report--4e7442f0-8797-5678-9aa0-4795b2c61d6f

Feed Name: TRU Security by Acronis

Threat Score
76/100

Date Published: 2025-06-18

Date Updated: 2026-07-25

...
...

Shadow Vector is an active, regionally focused malware campaign targeting users in Colombia via malicious SVG attachments and public-hosted stagers; it delivers multistage payloads (AsyncRAT, RemcosRAT and memory-resident .NET loaders) using DLL side-loading, vulnerable kernel drivers for escalation, UAC bypasses, process injection and in-memory execution, enabling credential theft, keylogging and full remote access while leaving minimal disk artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.