Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks
ID: 686fdfb9-0423-5619-9328-d3025244785f
STIX ID: report--686fdfb9-0423-5619-9328-d3025244785f
Feed Name: GBHackers
Elastic Security Labs observed an intrusion against a South Asian financial institution leveraging a custom toolkit: BRUSHWORM, a modular backdoor that implements scheduled-task persistence, modular DLL loading, USB propagation, and bulk document theft; and BRUSHLOGGER, a libcurl.dll side‑loaded 32-bit keylogger that captures keystrokes with per-window context and writes XOR-obfuscated logs. The report notes multiple testing builds on VirusTotal, weak obfuscation, hardcoded paths/keys, and limited telemetry from the victim environment, indicating an active but somewhat unsophisticated actor iterating on their tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
