logo

New Malware Uses Obfuscation and Staged Payload Delivery to Evade Detection

ID: 7b4e9fd1-b019-5993-9eb7-4c360132787e

STIX ID: report--7b4e9fd1-b019-5993-9eb7-4c360132787e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Tushar Subhra Dutta

...
...

A targeted spear-phishing campaign against Punjab government staff used a misspelled Word document with VBA stomping and a fake Adobe PDF update delivering a custom remote-access payload hosted on BunnyCDN; the malware establishes persistence, exfiltration-capable functionality, and uses Microsoft VS Code tunnels for covert command-and-control and Discord webhooks for attacker notifications, with sandbox and detection telemetry confirming malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.