logo

APT37’s New “Python-in-a-Cat” Malware Uses Environment Variable Obfuscation

ID: 16e8acbe-0529-53e1-97b8-2ae0d382a00a

STIX ID: report--16e8acbe-0529-53e1-97b8-2ae0d382a00a

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

Genians Security Center deconstructed a targeted APT37-linked spear-phishing campaign that delivers ZIP-compressed malicious .LNK files which call environment-variable–obfuscated batch scripts to dynamically reconstruct and download a compiled Python implant (disguised with a .cat extension); the multi-stage memory-reconstruction, persistent C2 communication, and frequent infrastructure rotation enable stealthy, long-term compromise and the report urges strengthening behavior-based EDR to detect obfuscation and staged download abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.