Fileless Python Malware Uses Humanitarian Lures to Deploy Full-Spectrum Surveillance
ID: 127eb05d-ba4c-5323-a848-8b0525662fd6
STIX ID: report--127eb05d-ba4c-5323-a848-8b0525662fd6
Feed Name: securityonline.info
Threat Score
Cyble Research reports a targeted cyberespionage campaign leveraging humanitarian-themed phishing (Russian-language lures) that delivers a fileless, heavily obfuscated Python implant via a malicious LNK in a RAR archive; the operators stage payloads from GitHub Releases, use PyArmor obfuscation, a Flask C2, and scheduled tasks for persistence to perform continuous surveillance, credential and file theft, keystroke logging, and live remote desktop access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
