BLISTER Loader
ID: 838d440e-9b7b-546a-b6fe-7d724879ad76
STIX ID: report--838d440e-9b7b-546a-b6fe-7d724879ad76
Feed Name: Elastic Security Labs
Elastic Security provides a technical analysis of the BLISTER Windows loader, describing how it embeds malicious code into legitimate DLLs, deciphers a second stage from resources, applies heavy anti-analysis techniques, and supports multiple persistence and injection methods (shellcode, reflective loading, process hollowing). The report documents BLISTER’s active development and use to load diverse malware families (ransomware, info-stealers, Cobalt Strike, etc.), supplies a configuration structure, indicators (SHA256), an updated YARA rule, and an open-source extractor to retrieve embedded payloads for threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
