New ‘BlackSanta’ EDR killer spotted targeting HR departments
ID: 436de6cf-38d8-538d-a950-2972cddcd968
STIX ID: report--436de6cf-38d8-538d-a950-2972cddcd968
Feed Name: Bleeping Computer
Threat Score
A Russian-speaking threat actor ran a year-long spear-phishing campaign targeting HR departments that delivered a sophisticated EDR-killer called BlackSanta. The attack chain used malicious ISO files (LNK launching PowerShell), steganography, DLL sideloading, process hollowing, and brought in kernel-capable drivers (RogueKiller, IObitUnlocker) to terminate security processes, weaken Defender settings, and exfiltrate sensitive data while avoiding detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
