Hackers Deploy BRUSHWORM and BRUSHLOGGER Against South Asian Financial Firm
ID: e6c932fd-c5ab-5592-a532-629f14db1831
STIX ID: report--e6c932fd-c5ab-5592-a532-629f14db1831
Feed Name: cybersecurityNews.com
A South Asian financial institution was targeted by a focused intrusion employing two bespoke tools: BRUSHWORM, a modular backdoor that establishes persistence (scheduled tasks MSGraphics/MSRecorder), fetches and loads DLL payloads, steals documents, and propagates via USB using socially engineered filenames; and BRUSHLOGGER, a DLL side-loaded keylogger that captures keystrokes and active window titles. Researchers observed limited SIEM visibility, weak code quality suggesting an inexperienced author, evidence of development artifacts on VirusTotal, and provide detection guidance (monitor scheduled task creation, DLL loading behavior, USB activity) plus YARA rules to identify the malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
