logo

Sophisticated Attack Campaign Exposes Loader Used by Multiple Threat Actors

ID: f3659fb6-77a4-59dd-a353-4639854c50b3

STIX ID: report--f3659fb6-77a4-59dd-a353-4639854c50b3

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2025-12-19

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Cyble researchers describe a sophisticated, targeted campaign using a standardized commodity loader shared by multiple high-capability threat actors to deliver RATs and infostealers. The campaign leverages steganography to hide payloads in images, string reversal/Base64 obfuscation, abuse of legitimate .NET executables for process hollowing, and a novel UAC bypass; targets include manufacturing and government entities in Europe and the Middle East, with IoCs and TTP mappings provided in the full report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.