logo

New Malware Hides Behind Obfuscation and Staged Payloads

ID: ff7e9b48-f6df-5db9-812c-d0fa72e97105

STIX ID: report--ff7e9b48-f6df-5db9-812c-d0fa72e97105

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Mayura Kathir

...
...

A targeted malware campaign against Punjab Safe Cities Authority and PPIC3 in Pakistan leverages spear-phishing with misspelled attachments (malicious Word macro and a malicious ClickOnce-distributed PDF) to deliver multi-stage payloads (code.exe / Adobe.exe). The malware employs VBA stomping, CDN-hosted delivery, Visual Studio Code tunnels for C2, and Discord webhooks for data exfiltration, combining evasion and persistence techniques that resulted in confirmed payload execution and high detection scores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.