New Malware Uses Obfuscation and Staged Payload Delivery to Evade Detection
ID: 7b4e9fd1-b019-5993-9eb7-4c360132787e
STIX ID: report--7b4e9fd1-b019-5993-9eb7-4c360132787e
Feed Name: cybersecurityNews.com
Threat Score
A targeted spear-phishing campaign against Punjab government staff used a misspelled Word document with VBA stomping and a fake Adobe PDF update delivering a custom remote-access payload hosted on BunnyCDN; the malware establishes persistence, exfiltration-capable functionality, and uses Microsoft VS Code tunnels for covert command-and-control and Discord webhooks for attacker notifications, with sandbox and detection telemetry confirming malicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
