logo

Technical Analysis of Code-Signed “Blister” Malware Campaign (Part 2)

ID: 282f7833-1d4e-53dd-8a0b-0fb8bc2b388c

STIX ID: report--282f7833-1d4e-53dd-8a0b-0fb8bc2b388c

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2022-02-17

Date Updated: 2026-04-27

...
...

The report analyzes the Blister malware campaign (active since 15 Sep 2021), detailing a code-signed dropper that writes a malicious DLL to Temp, decodes a staged PE payload from resources, employs anti-analysis sleep and heavy obfuscation, and executes the payload via process hollowing into a renamed rundll32.exe. Final-stage payloads observed include information stealers (Raccoon), Cobalt Strike beacons, and BitRAT; persistence is achieved by installing a startup .lnk. The analysis highlights IoCs and recommends updating endpoint/network defenses to detect these behaviors and signed binaries used maliciously.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.