HR Departments Targeted by Multi-Layered BlackSanta EDR Killer Malware
ID: e180dbb7-c261-58be-bee8-1a09d17204ff
STIX ID: report--e180dbb7-c261-58be-bee8-1a09d17204ff
Feed Name: GBHackers
The report describes a sophisticated campaign that targets HR teams by sending supposedly legitimate resumes hosted on cloud storage which are actually ISO images containing malicious LNK files. Opening the ISO triggers obfuscated PowerShell which extracts a steganography-hidden payload and sideloads a malicious DLL; the toolkit includes BlackSanta, a BYOVD-capable component that disables endpoint protections at the kernel level, performs fileless in-memory execution, and exfiltrates sensitive artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
