logo

Brushaloader gaining new layers like a pro

ID: 82a3cece-1862-5751-a7ab-d981b7b9fe78

STIX ID: report--82a3cece-1862-5751-a7ab-d981b7b9fe78

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2019-11-19

Date Updated: 2026-04-19

Author: Michał Praszmo

...
...

This report analyzes a 2019 Polish-targeted malspam campaign that used a malicious XLS document as a first-stage dropper to deliver Brushaloader, which then deployed an ISFB v2 banking trojan. The author walks through macro extraction, PowerShell deobfuscation, C2 interaction that returns an XOR-encrypted VBScript dropper, and the static config used to download webinjects and redirects for Polish banks and email providers; sample hashes and helper scripts are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.