FakeBat Loader Malware Spreads Widely Through Drive-by Download Attacks
ID: 0c4354cc-53a4-5677-bf61-249364b76fc2
STIX ID: report--0c4354cc-53a4-5677-bf61-249364b76fc2
Feed Name: The Hacker News
The report describes widespread distribution of the FakeBat loader-as-a-service (aka EugenLoader/PaykLoader) via drive-by downloads, SEO poisoning, malvertising, compromised websites, and social engineering to deliver numerous secondary payloads (IcedID, RedLine, Ursnif, Lumma, SmokeLoader, etc.). It highlights FakeBat's commercialization and evasion techniques (shift to MSIX and use of valid digital signatures to bypass SmartScreen), links to likely activity clusters (FIN7, Nitrogen, BATLOADER), and related loader campaigns (DBatLoader, Hijack Loader) used to drop info-stealers and RATs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
