Attackers Adopting Novel LOTL Techniques to Evade Detection
ID: 5a6f5ced-dd5e-5ab5-8546-009759115fc4
STIX ID: report--5a6f5ced-dd5e-5ab5-8546-009759115fc4
Feed Name: Infosecurity Magazine (News)
HP Wolf's Q2 2025 Threat Insights report documents several active, evolving malware campaigns that chain living-off-the-land tools to evade detection—notably an XWorm RAT hidden in image pixels and executed via MSBuild, SVG-based browser lures that fetch obfuscated JavaScript, and Lumma Stealer distributed in IMG archives and installed via NSIS—highlighting novel TTPs (steganography, uncommon binaries, geofencing, multi-stage PowerShell/HTA/NSIS chains) and ongoing operator activity despite prior takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
