Cybercriminals Exploit Maduro Arrest News to Spread Backdoor Malware
ID: 222cb129-406a-56e1-8c48-bbf56dd3ec22
STIX ID: report--222cb129-406a-56e1-8c48-bbf56dd3ec22
Feed Name: GBHackers
Security researchers observed a spear-phishing campaign exploiting reports of Venezuelan President Nicolás Maduro’s arrest to deliver a backdoor. The lure contains a ZIP with a KuGou executable and a malicious DLL (kugou.dll) that achieves persistence via DLL search-order hijacking, copies itself to C:\ProgramData\Technology360NB, creates an autorun registry entry (HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Lite360), forces a reboot, and beacons to a C2 at 172.81.60.97:443. The report lists file hashes for the archive, executable, and DLL as IoCs and notes tactic similarities to known Chinese threat activity but stops short of attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
