logo

Threat Actors Exploit Commodity Loader in Targeted Email Campaigns Against Organizations

ID: 0388b8ac-3454-5bdc-9a19-35b9b2126b7c

STIX ID: report--0388b8ac-3454-5bdc-9a19-35b9b2126b7c

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Cyble Research and Intelligence Labs reports a coordinated, multi-stage email campaign leveraging weaponized Office docs, malicious SVGs, and steganographically stored payloads to deliver a shared commodity loader that deploys multiple RATs and infostealers (notably PureLog Stealer) against manufacturing and government targets in Italy, Finland, and Saudi Arabia, employing advanced evasion techniques (obfuscation, trojanized .NET assemblies, process hollowing, and a novel UAC bypass).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.