logo

Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware

ID: f5d7e3a6-8c5d-5cc6-9e08-ca97c2b0a019

STIX ID: report--f5d7e3a6-8c5d-5cc6-9e08-ca97c2b0a019

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-10

Date Updated: 2026-04-21

Author: Dhivya

...
...

The report details a geopolitical-themed spear-phishing campaign using a zip attachment (“US now deciding what’s next for Venezuela.zip”) that contains a weaponized KuGou executable and a malicious kugou.dll which is loaded via DLL hijacking to install a backdoor; the malware creates C:\ProgramData\Technology360NB, persists via HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Lite360, prompts a restart to trigger the payload, and regularly connects to C2 at 172.81.60.97:443. IoCs (IP and file hashes) are provided and researchers note similarities to prior Mustang Panda activity but do not attribute definitively.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.