logo

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

ID: 9bf0fc3a-4c8e-57f4-b0a0-7064be513d4a

STIX ID: report--9bf0fc3a-4c8e-57f4-b0a0-7064be513d4a

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-09-17

Date Updated: 2026-09-18

...
...

This analysis documents a malspam phishing attachment containing an obfuscated JavaScript dropper that writes two temporary files and passes their paths via process environment variables to a PowerShell stage; the PowerShell stage decrypts and decompresses a 64-bit .NET loader which performs AMSI bypass and extracts an embedded RC4-encrypted second .NET downloader that attempts to fetch a steganographically-embedded PE from a PNG (potentially executed via reflective loading or process hollowing). The report provides file hashes, the filename, a download URL, detailed TTP mappings to MITRE ATT&CK, and notes on persistence via a scheduled task.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.