logo

Kernel in the Crosshairs: The BlackSanta Threat Campaign Targeting Recruitment Workflows

ID: c2223a5d-dfb6-5a40-9d86-d160e80c4f3c

STIX ID: report--c2223a5d-dfb6-5a40-9d86-d160e80c4f3c

Feed Name: Aryaka

Threat Score
80/100

Date Published: 2026-03-10

Date Updated: 2026-04-27

Author: Aditya K Sood

...
...

This report describes the 'BlackSanta' campaign that targets recruitment workflows by delivering resume-themed ISO files which launch malicious LNK shortcuts to execute obfuscated PowerShell, extract steganographic payloads, sideload a malicious DLL, and establish encrypted C2; a standout component is a BYOVD-based kernel module that uses signed vulnerable drivers to disable antivirus and EDR protections, enabling credential harvesting and stealthy data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.