Kiss Loader Malware Targets with Early Bird APC Injection in New Attack Campaign
ID: 41b1117e-06e1-597f-9f19-b759bacc0959
STIX ID: report--41b1117e-06e1-597f-9f19-b759bacc0959
Feed Name: GBHackers
Threat Score
Kiss Loader is a newly discovered, actively developed multi-stage loader that leverages open WebDAV delivered via Cloudflare tunnels to stage encrypted payloads, uses WSH/JScript and Python components to deploy and decrypt payloads (including RAT variants), and achieves stealthy in-memory execution through Donut-generated shellcode and Early Bird APC injection; the analysis documents live operator interaction and provides multiple IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
