APT37’s New “Python-in-a-Cat” Malware Uses Environment Variable Obfuscation
ID: 16e8acbe-0529-53e1-97b8-2ae0d382a00a
STIX ID: report--16e8acbe-0529-53e1-97b8-2ae0d382a00a
Feed Name: securityonline.info
Genians Security Center deconstructed a targeted APT37-linked spear-phishing campaign that delivers ZIP-compressed malicious .LNK files which call environment-variable–obfuscated batch scripts to dynamically reconstruct and download a compiled Python implant (disguised with a .cat extension); the multi-stage memory-reconstruction, persistent C2 communication, and frequent infrastructure rotation enable stealthy, long-term compromise and the report urges strengthening behavior-based EDR to detect obfuscation and staged download abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
