logo

Package deal: Malware bundles causing disruption and damage across EMEA

ID: d6f907f9-cfd2-5e12-9358-afc51b2d7c62

STIX ID: report--d6f907f9-cfd2-5e12-9358-afc51b2d7c62

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2023-02-17

Date Updated: 2026-04-27

...
...

Group-IB analyzed a series of 'malware bundle' incidents in EMEA where single downloadable packages delivered combinations of downloaders, info-stealers (notably RedLine and Vidar), RATs, loaders, and DJVU/STOP ransomware; delivery was via phishing, malicious file-sharing sites and Discord CDN, with C2 infrastructure using HTTP, net.tcp, Telegram and Mastodon channels. The report maps observed behaviors to MITRE ATT&CK (execution, persistence, defense evasion, C2, exfiltration, impact), lists IoCs (IPs, domains, URLs), describes escalation pathways (IABs, meterpreter, rootkits), and provides both individual- and enterprise-focused mitigation guidance including EDR/XDR, patching, MFA/VPN, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.