New TicTacToe Dropper Steals Data, Spreads Multiple Threats on Windows
ID: f96747ef-2dfe-5eee-83b0-a05219c5845b
STIX ID: report--f96747ef-2dfe-5eee-83b0-a05219c5845b
Feed Name: HackRead
Threat Score
FortiGuard Labs identified a multi-stage Windows malware loader dubbed the TicTacToe dropper that has been active across 2023–2024 and drops multiple final-stage payloads (AgentTesla, LokiBot, Remcos, and others). The dropper uses .iso delivery to evade detection, extracts nested DLL layers at runtime, and employs obfuscation tools (DeepSea, SmartAssembly) and reflective loading; researchers note dynamic string changes and recommend behavior-based EDR for new campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
