logo

Fake Screenshot Lures Target Web3 Support Staff with Multi-Stage Malware Attack

ID: 44f403f5-9dd7-540e-9289-380a9fa520f1

STIX ID: report--44f403f5-9dd7-540e-9289-380a9fa520f1

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report documents an active, sophisticated campaign (linked to APT‑Q‑27/GoldenEyeDog) that targets Web3 support teams by sending look‑alike screenshot links which execute signed .NET loaders; those loaders retrieve manifests from AWS S3 dead drops and stage a DLL sideloading chain that unpacks a memory‑resident Farfli backdoor communicating with 37 hard‑coded C2 IPs over TCP/15628. The writeup includes detailed TTPs (obfuscation, anti‑debug checks, Run registry persistence, service 'Windows Eventn', UAC tampering), IOCs (filenames and SHA256 hashes), and actionable defenses (block C2 traffic, enforce visible file extensions, sandbox support workflows, EDR coverage).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.