logo

Stealth In Layers: Unmasking The Loader Used In Targeted Email Campaigns

ID: d2a1c4f3-0a3e-5468-830e-dd8ec396f854

STIX ID: report--d2a1c4f3-0a3e-5468-830e-dd8ec396f854

Feed Name: Cyble Blog

Threat Score
82/100

Date Published: 2026-06-09

Date Updated: 2026-07-17

...
...

**Executive summary:** CRIL details a targeted, multi-stage malware campaign leveraging weaponized email attachments and steganographically embedded payloads to reflectively load a trojanized .NET TaskScheduler assembly that performs process hollowing and delivers Remote Access Trojans and PureLog Stealer; the report documents a novel UAC bypass, comprehensive MITRE mappings, and actionable IOCs (hashes, URLs, IP) affecting manufacturing and government organizations in Italy, Finland, and Saudi Arabia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.