logo

Active HanGhost Loader Campaign Targets Enterprise Payment and Logistics Workflows

ID: 75b9088f-06ae-5aeb-97d5-cfeb160d4363

STIX ID: report--75b9088f-06ae-5aeb-97d5-cfeb160d4363

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Owais Sultan

...
...

An active HanGhost loader campaign uses obfuscated JavaScript and hidden PowerShell to run a .NET in-memory loader that extracts encrypted payloads from images, delivering multiple malware families (PureHVNC, XWorm, Meduza, AgentTesla, Phantom and sometimes UltraVNC). The threat specifically targets finance and operations personnel to gain persistent remote access and steal or manipulate transactional and contractual data; the report recommends behavior-first triage (interactive sandboxing) and hunting based on execution chains rather than static indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.