logo

Tactical Misdirection: The “Hologram” Malware Framework Hijacking AI Enthusiasts

ID: e5cee8ca-4585-55b9-a4b4-2523f768a12e

STIX ID: report--e5cee8ca-4585-55b9-a4b4-2523f768a12e

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

Netskope Threat Labs uncovered a sophisticated multi-wave campaign (Hologram → Pathfinder) that has progressed from simple credential stealers to a modular infostealer framework targeting over 250 crypto wallet and password-manager extensions. The operators employ advanced evasion and persistence techniques (CLR injection, reflective PE loading, NT syscall thread injection, WinLogon/COM hijacking), abuse legitimate services for payload hosting and C2 (Azure DevOps, Telegram, Hookdeck), and deployed stage-2 binaries including vicloud.exe (Vidar) and an emerging dbau.exe while rotating infrastructure to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.