Revisiting BLISTER: New development of the BLISTER loader
ID: 7945d3a8-38af-523e-9e65-a3cb8352f5a0
STIX ID: report--7945d3a8-38af-523e-9e65-a3cb8352f5a0
Feed Name: Elastic Security Labs
Elastic Security Labs analyzes the evolving BLISTER malware loader, detailing new capabilities including environment-specific execution (domain hashing), unhooking of process instrumentation to evade userland syscall detection, configurable anti-debug timing, revised configuration structure, and changes to hashing. The report documents BLISTER's use to smuggle malicious code into legitimate libraries (e.g., VLC DLL), its deployment of MYTHIC implants in recent campaigns, low detection rates, provided YARA rules, and downloadable observables for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
