Multi-Malware 'Cluster Bomb' Campaign Drops Widespread Cyber Havoc
ID: d4d6c79d-660a-502d-88f5-d5e6158af4fa
STIX ID: report--d4d6c79d-660a-502d-88f5-d5e6158af4fa
Feed Name: Dark Reading
A financially motivated East European actor called "Unfurling Hemlock" has been running a widespread "cluster bomb" campaign since at least February 2023 that uses nested Microsoft CAB files (often several layers deep) unpacked via weextract.exe to drop multiple malware payloads simultaneously — including information stealers (Mystic Stealer, Rise Pro, Redline) and loaders (SmokeLoader, Amadey) — across roughly 50,000 victims worldwide, primarily in the US; the campaign also employs EDR/Defender disabling tools and both distributes others' malware and leverages partners to disseminate its own, complicating detection and eradication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
