Threat Actors Exploit Commodity Loader in Targeted Email Campaigns Against Organizations
ID: 0388b8ac-3454-5bdc-9a19-35b9b2126b7c
STIX ID: report--0388b8ac-3454-5bdc-9a19-35b9b2126b7c
Feed Name: GBHackers
Threat Score
Cyble Research and Intelligence Labs reports a coordinated, multi-stage email campaign leveraging weaponized Office docs, malicious SVGs, and steganographically stored payloads to deliver a shared commodity loader that deploys multiple RATs and infostealers (notably PureLog Stealer) against manufacturing and government targets in Italy, Finland, and Saudi Arabia, employing advanced evasion techniques (obfuscation, trojanized .NET assemblies, process hollowing, and a novel UAC bypass).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
