logo

Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

ID: da7f2e74-7f90-58e3-ab34-f8fbd091899b

STIX ID: report--da7f2e74-7f90-58e3-ab34-f8fbd091899b

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-27

...
...

**Executive summary:** Elastic Security Labs identified two custom malware components used against a South Asian financial institution: BRUSHWORM (a modular backdoor with scheduled‑task persistence, WinHTTP C2/payload download, USB propagation, and broad file theft with staging and hash tracking) and BRUSHLOGGER (a DLL side‑loading keylogger that captures window context and XOR‑encoded logs); the report provides behavioral details, YARA rules, IoCs, and evidence of iterative development and active C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.