logo

Attackers Adopting Novel LOTL Techniques to Evade Detection

ID: 5a6f5ced-dd5e-5ab5-8546-009759115fc4

STIX ID: report--5a6f5ced-dd5e-5ab5-8546-009759115fc4

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-09-12

Date Updated: 2026-04-22

...
...

HP Wolf's Q2 2025 Threat Insights report documents several active, evolving malware campaigns that chain living-off-the-land tools to evade detection—notably an XWorm RAT hidden in image pixels and executed via MSBuild, SVG-based browser lures that fetch obfuscated JavaScript, and Lumma Stealer distributed in IMG archives and installed via NSIS—highlighting novel TTPs (steganography, uncommon binaries, geofencing, multi-stage PowerShell/HTA/NSIS chains) and ongoing operator activity despite prior takedowns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.