Inside a Multi-Stage Windows Malware Campaign
ID: 97b8781c-40d1-5424-897f-75fb4a342d5e
STIX ID: report--97b8781c-40d1-5424-897f-75fb4a342d5e
Feed Name: Fortinet Blog
FortiGuard Labs documents a sophisticated, multi-stage malware campaign targeting Windows users—primarily in Russia—where malicious LNK files launch PowerShell to fetch staged scripts hosted on GitHub and Dropbox. The chain hides execution with decoy documents, disables Microsoft Defender (including abusing Defendnot), establishes persistence and surveillance via Amnesia RAT (credential/session theft, clipboard monitoring, screenshots), then deploys Hakuna Matata–derived ransomware and a WinLocker to encrypt files, destroy recovery artifacts, and coerce victims; the report includes detailed TTPs, MITRE ATT&CK mappings, and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
