The Malware That Chats Back: Inside G DATA’s Real-Time Notepad Encounter with the “Kiss Loader” Author
ID: 94fed05a-ac14-503d-a350-55f0f5ef2ba7
STIX ID: report--94fed05a-ac14-503d-a350-55f0f5ef2ba7
Feed Name: securityonline.info
Kiss Loader is a Python-based loader delivered via a deceptive Windows Internet Shortcut that fetches payloads from a TryCloudflare-hosted WebDAV, persists via the Startup folder, decrypts Donut-generated shellcode, and performs Early Bird APC injection into a suspended legitimate process to run payloads (VenomRAT and a .NET utility). The analysis uniquely documented a real-time Notepad conversation with the apparent author, confirming development activity and use of the described techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
