Havoc Stager Campaign Exploits Fake Invoices to Compromise Networks
ID: 29b9ae8d-dda7-5747-883d-46b126769bd3
STIX ID: report--29b9ae8d-dda7-5747-883d-46b126769bd3
Feed Name: securityonline.info
A regional campaign dubbed the "Havoc stager" delivers malicious archives disguised as Brazilian electronic invoices; a script downloads an installer that places a signed legitimate app alongside a malicious DLL, abusing Windows DLL search order to sideload attacker code. The stager fetches a memory-resident backdoor from C2, employs evasion techniques (stack-frame spoofing, indirect syscalls), persists via unusual registry keys, and appears produced by a shared builder used across multiple distribution operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
