HR, recruiters targeted in year-long malware campaign
ID: 13d49f1a-fb85-5be2-bfed-54d88dca05ff
STIX ID: report--13d49f1a-fb85-5be2-bfed-54d88dca05ff
Feed Name: Help Net Security
**Resume-themed ISO lure leads to stealthy EDR-killer campaign**: Researchers uncovered a low-noise, Russian-speaking threat actor using resume-themed ISO attachments to mount a multi-stage infection (PowerShell, steganography, DLL sideloading) that downloads a DWrite.dll component and a previously undocumented BlackSanta EDR killer; BlackSanta abuses vulnerable kernel drivers to neutralize endpoint detection and likely enables follow-on information-stealing payloads, while the actor deliberately avoids sandbox/analysis and excludes victims in Russia/CIS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
