logo

Intelligence Insights: February 2025

ID: c45f3d44-1b38-56a6-ade9-953e2ff69ea2

STIX ID: report--c45f3d44-1b38-56a6-ade9-953e2ff69ea2

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2025-02-20

Date Updated: 2026-04-29

Author: The Red Canary Team

...
...

Red Canary documents Saffron Starling, a loader observed delivering payloads including Danabot, DarkGate, and Matanbuchus, and highlights a detection opportunity where wscript/cscript/mshta launch PowerShell to download and execute payloads. The report also reevaluates prior ChromeLoader activity, reclassifying a recent campaign as a Browser Assistant variant (a potentially unwanted program) that shares file structure and obfuscation with traditional Browser Assistant but exhibits PDF-themed masquerading, suspicious install paths, and occasional differing signing certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.