Hello again, FakeBat: popular loader returns after months-long hiatus
ID: de96d676-e0cd-5aed-bdfa-d08fe1fb49ca
STIX ID: report--de96d676-e0cd-5aed-bdfa-d08fe1fb49ca
Feed Name: Malwarebytes Blog
Threat Score
Malwarebytes observed a malvertising campaign using a spoofed Notion Google ad that delivered the FakeBat loader (aka EugenLoader/PaykLoader), which decrypts and injects a LummaC2 stealer into MSBuild.exe after multi-stage PowerShell execution and AMSI bypass; the report includes detailed TTPs and multiple IOCs (malicious URLs, file hashes, and C2 domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
