APT-Q-27 Targeting Corporate Environments in Stealthy Attack Without Triggering Alerts
ID: 388ffc8d-6e1d-51b1-9098-0f64921d6ca7
STIX ID: report--388ffc8d-6e1d-51b1-9098-0f64921d6ca7
Feed Name: cybersecurityNews.com
**CyStack** reported a mid-January 2026 targeted, highly stealthy malware campaign against financial institutions attributed to APT-Q-27 (GoldenEyeDog); the intrusion began via a malicious Zendesk ticket link delivering a disguised .pif executable that used a timestamped signed certificate to bypass SmartScreen, then performed DLL sideloading (crashreport.dll) and in-memory execution from a deceptive Windows Update–like staging directory, enabling persistent C2 and modular payload delivery while avoiding typical endpoint detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
