AveMaria's Distribution Strategy
ID: c795b9f7-8b1c-55e4-8fe5-91dfa67fdec1
STIX ID: report--c795b9f7-8b1c-55e4-8fe5-91dfa67fdec1
Feed Name: Zscaler Security Research Blog
This report analyzes multiple AveMaria infostealer campaigns (July–December 2022), presenting case studies that document phishing delivery vectors (malicious VHD/VHDX, ISO, ZIP attachments and shortcut/HTA files), multi-stage loaders and decryption routines, process injection and persistence techniques, and targeted activity against Kazakhstan, Ukraine, and Serbian victims; it includes behavioral analysis, decryption logic, and artifacts useful for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
