New Unfurling Hemlock threat actor floods systems with malware
ID: d9eb653d-2c62-587f-884d-a704fdaf8562
STIX ID: report--d9eb653d-2c62-587f-884d-a704fdaf8562
Feed Name: Bleeping Computer
Outpost24's KrakenLabs uncovered a long-running (since at least Feb 2023) Unfurling Hemlock campaign that uses a nested CAB 'cluster bomb' delivered via WEXTRACT.EXE to drop multiple malware payloads (including Redline, RisePro, Mystic Stealer, loaders like SmokeLoader and Amadey, and utilities that disable protections), affecting primarily US targets and other countries; researchers observed tens of thousands of related files and note indicators (Russian language in samples, AS203727 hosting) pointing to an Eastern European base.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
