logo

CharmingCypress: Innovating Persistence

ID: c656e276-5a7b-5c96-9b45-c875bacc155d

STIX ID: report--c656e276-5a7b-5c96-9b45-c875bacc155d

Feed Name: Volexity Blog

Threat Score
88/100

Date Published: 2024-02-13

Date Updated: 2026-05-01

...
...

Volexity documents targeted CharmingCypress spear-phishing campaigns that employ sophisticated social engineering and technical TTPs—including fake webinar portals and malware-laden VPN clients—to deploy multiple backdoors (POWERLESS, NOKNOK, BASICSTAR, POWERSTAR, EYEGLASS). The report describes infection chains (RAR+LNK, staged PowerShell/.NET components), persistence and exfiltration capabilities, C2 domains and file hashes, and memory-forensic evidence of active compromise against journalists, policy experts, and research organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.