logo

Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks

ID: 686fdfb9-0423-5619-9328-d3025244785f

STIX ID: report--686fdfb9-0423-5619-9328-d3025244785f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Elastic Security Labs observed an intrusion against a South Asian financial institution leveraging a custom toolkit: BRUSHWORM, a modular backdoor that implements scheduled-task persistence, modular DLL loading, USB propagation, and bulk document theft; and BRUSHLOGGER, a libcurl.dll side‑loaded 32-bit keylogger that captures keystrokes with per-window context and writes XOR-obfuscated logs. The report notes multiple testing builds on VirusTotal, weak obfuscation, hardcoded paths/keys, and limited telemetry from the victim environment, indicating an active but somewhat unsophisticated actor iterating on their tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.