logo

Inside the BRUSHWORM Malware Campaign Bridging Air-Gaps with USB “Sleeper” Cells

ID: ed8691b4-5cb2-59df-89e6-6f9a4466d5de

STIX ID: report--ed8691b4-5cb2-59df-89e6-6f9a4466d5de

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Elastic Security Labs identified a targeted campaign against a South Asian financial institution using two custom tools: BRUSHWORM, a modular backdoor that persists via a scheduled task and propagates to USB drives for offline exfiltration, and BRUSHLOGGER, a libcurl.dll‑masquerading keylogger that records window context and stores XOR-encrypted logs; despite coding flaws that suggest an inexperienced author, the campaign is operational and poses a significant data-theft risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.