logo

The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP

ID: 7f24b9c7-e3aa-5a6d-a5cf-cc25a5b3ca65

STIX ID: report--7f24b9c7-e3aa-5a6d-a5cf-cc25a5b3ca65

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

Author: Jose Martin

...
...

LevelBlue SpiderLabs reports a Brazil-focused malspam campaign that uses invoice-shaped ZIP attachments and a fake Microsoft Defender DLP installer to deploy an unsigned stager (endpointdlp.dll) which fetches Havoc implants over the network (never written to disk). The analysis links nine stager variants to a single builder, enumerates persistence via UserInitMprLogonScript, describes Havoc’s anti-forensic features (memory masking, indirect syscalls, AMSI/ETW patching), and publishes YARA and IOCs to detect the stager and related infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.