logo

Disney security breach

ID: ef32afda-a715-5537-bd02-3cef26a66039

STIX ID: report--ef32afda-a715-5537-bd02-3cef26a66039

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

Threat actor group "Nullbulge" reportedly compromised Disney by leveraging an insider who had exported or stored credentials and by distributing malicious packages: a malicious Beam.NG mod that executed a PowerShell payload and a trojanized ComfyUI extension that replaced OpenAI/Anthropic libraries to exfiltrate API keys and deploy a payload. ThreatLocker analysis links the intrusions to known RATs and info stealers (AsyncRAT, LockBit payloads), provides multiple SHA-256 IOCs and a hosting URL, and recommends hardening password manager usage, MFA, application allowlisting, ringfencing, and EDR detection to mitigate similar attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.