Intelligence Insights: February 2025
ID: c45f3d44-1b38-56a6-ade9-953e2ff69ea2
STIX ID: report--c45f3d44-1b38-56a6-ade9-953e2ff69ea2
Feed Name: Red Canary
Red Canary documents Saffron Starling, a loader observed delivering payloads including Danabot, DarkGate, and Matanbuchus, and highlights a detection opportunity where wscript/cscript/mshta launch PowerShell to download and execute payloads. The report also reevaluates prior ChromeLoader activity, reclassifying a recent campaign as a Browser Assistant variant (a potentially unwanted program) that shares file structure and obfuscation with traditional Browser Assistant but exhibits PDF-themed masquerading, suspicious install paths, and occasional differing signing certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
