Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware
ID: f5d7e3a6-8c5d-5cc6-9e08-ca97c2b0a019
STIX ID: report--f5d7e3a6-8c5d-5cc6-9e08-ca97c2b0a019
Feed Name: cybersecurityNews.com
The report details a geopolitical-themed spear-phishing campaign using a zip attachment (“US now deciding what’s next for Venezuela.zip”) that contains a weaponized KuGou executable and a malicious kugou.dll which is loaded via DLL hijacking to install a backdoor; the malware creates C:\ProgramData\Technology360NB, persists via HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Lite360, prompts a restart to trigger the payload, and regularly connects to C2 at 172.81.60.97:443. IoCs (IP and file hashes) are provided and researchers note similarities to prior Mustang Panda activity but do not attribute definitively.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
