Multistage Loader used to spread AZORult and NanoCore
ID: 0b9baaf6-ce1c-580f-a47e-6891b2bc5edb
STIX ID: report--0b9baaf6-ce1c-580f-a47e-6891b2bc5edb
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report documents an active multistage campaign (Mar 2020) distributing AZORult and NanoCore via malicious PowerPoint macros that fetch obfuscated scripts from Pastebin and use mshta, VBScript, PowerShell, and a .NET 'FreeDom' loader to inject infostealer payloads (process hollowing into notepad.exe); it includes persistence behaviors, updated encoding variants, IOCs (MD5s, C2 IPs, Pastebin users), and regional targeting (South Korea, Indonesia).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
