logo

New Unfurling Hemlock threat actor floods systems with malware

ID: d9eb653d-2c62-587f-884d-a704fdaf8562

STIX ID: report--d9eb653d-2c62-587f-884d-a704fdaf8562

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-06-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Outpost24's KrakenLabs uncovered a long-running (since at least Feb 2023) Unfurling Hemlock campaign that uses a nested CAB 'cluster bomb' delivered via WEXTRACT.EXE to drop multiple malware payloads (including Redline, RisePro, Mystic Stealer, loaders like SmokeLoader and Amadey, and utilities that disable protections), affecting primarily US targets and other countries; researchers observed tens of thousands of related files and note indicators (Russian language in samples, AS203727 hosting) pointing to an Eastern European base.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.