You've Got Malware: FINALDRAFT Hides in Your Drafts
ID: cd1f52e4-7ec0-553d-822a-91caabab1b54
STIX ID: report--cd1f52e4-7ec0-553d-822a-91caabab1b54
Feed Name: Elastic Security Labs
Elastic Security Labs describes a sophisticated malware suite—PATHLOADER (Windows loader) and FINALDRAFT (implant, with PE and ELF variants)—used in an espionage-focused campaign; the tools abuse Microsoft Graph/Outlook for C2, use layered encryption/obfuscation, support process injection, file exfiltration, proxying, and include modular components (PowerShell execution, Pass-the-Hash tooling). The report includes protocol/structural details, command tables, sample hashes and typosquatted domains, and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
