New Malware Hides Behind Obfuscation and Staged Payloads
ID: ff7e9b48-f6df-5db9-812c-d0fa72e97105
STIX ID: report--ff7e9b48-f6df-5db9-812c-d0fa72e97105
Feed Name: GBHackers
A targeted malware campaign against Punjab Safe Cities Authority and PPIC3 in Pakistan leverages spear-phishing with misspelled attachments (malicious Word macro and a malicious ClickOnce-distributed PDF) to deliver multi-stage payloads (code.exe / Adobe.exe). The malware employs VBA stomping, CDN-hosted delivery, Visual Studio Code tunnels for C2, and Discord webhooks for data exfiltration, combining evasion and persistence techniques that resulted in confirmed payload execution and high detection scores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
