Stealth In Layers: Unmasking The Loader Used In Targeted Email Campaigns
ID: d2a1c4f3-0a3e-5468-830e-dd8ec396f854
STIX ID: report--d2a1c4f3-0a3e-5468-830e-dd8ec396f854
Feed Name: Cyble Blog
**Executive summary:** CRIL details a targeted, multi-stage malware campaign leveraging weaponized email attachments and steganographically embedded payloads to reflectively load a trojanized .NET TaskScheduler assembly that performs process hollowing and delivers Remote Access Trojans and PureLog Stealer; the report documents a novel UAC bypass, comprehensive MITRE mappings, and actionable IOCs (hashes, URLs, IP) affecting manufacturing and government organizations in Italy, Finland, and Saudi Arabia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
