logo

MLTBackdoor Malware Family Fuels Ransomware Attacks

ID: 22ee83ba-1782-5a81-a1d1-da31f1f5cfb9

STIX ID: report--22ee83ba-1782-5a81-a1d1-da31f1f5cfb9

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

Zscaler ThreatLabz identified MLTBackdoor, a sophisticated backdoor associated with ransomware operators that uses ClickFix social engineering to deliver malicious PowerShell, employs heavy MBA and control-flow flattening obfuscation, supports Beacon Object Files for fileless capability, and maintains resilient, ECDH/AES-256-GCM encrypted C2 communications with a DGA fallback; organizations should monitor anomalous PowerShell activity and strengthen endpoint detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.