logo

Off the Beaten Path: Recent Unusual Malware

ID: 0fdc535b-5d06-5f8f-86b1-d4e1f947fab4

STIX ID: report--0fdc535b-5d06-5f8f-86b1-d4e1f947fab4

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-03-14

Date Updated: 2026-04-28

Author: Dominik Reichel

...
...

**Executive summary:** This Unit 42 report analyzes three notable malware examples discovered in 2023–2024: an uncommon C++/CLI IIS passive backdoor with AES-authenticated header commands and remote execution/file operations; a GRUB2-bootloader bootkit that abuses an unsecured kernel driver to write a boot image to disk and achieve persistence; and ProjectGeass, a large multi-platform post-exploitation/red-team beacon with file management, command execution, keylogging and configurable C2 — each sample is accompanied by technical indicators and hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.