SquidLoader Malware Campaign Targets Hong Kong Financial Sector
ID: af06c0db-02bf-55c8-9627-345b987c0519
STIX ID: report--af06c0db-02bf-55c8-9627-345b987c0519
Feed Name: Infosecurity Magazine (News)
A new campaign using SquidLoader targets financial institutions in Hong Kong with Mandarin spear-phishing emails containing password-protected RARs; the malicious PE masquerades as a Word-related binary, self-unpacks, dynamically resolves APIs, and employs extensive anti-analysis and sandbox-evasion techniques before contacting C2 infrastructure to download a Cobalt Strike Beacon and establish persistent remote access. Organizations are advised to strengthen email filtering, endpoint monitoring, and behavioral detection to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
