Off the Beaten Path: Recent Unusual Malware
ID: 0fdc535b-5d06-5f8f-86b1-d4e1f947fab4
STIX ID: report--0fdc535b-5d06-5f8f-86b1-d4e1f947fab4
Feed Name: Palo Alto Networks Unit 42
**Executive summary:** This Unit 42 report analyzes three notable malware examples discovered in 2023–2024: an uncommon C++/CLI IIS passive backdoor with AES-authenticated header commands and remote execution/file operations; a GRUB2-bootloader bootkit that abuses an unsecured kernel driver to write a boot image to disk and achieve persistence; and ProjectGeass, a large multi-platform post-exploitation/red-team beacon with file management, command execution, keylogging and configurable C2 — each sample is accompanied by technical indicators and hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
