logo

Ande Loader Malware Targets Manufacturing Sector in North America

ID: 55139a87-6219-59d9-9105-b1b6d1f717cb

STIX ID: report--55139a87-6219-59d9-9105-b1b6d1f717cb

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report details Blind Eagle (APT-C-36) expanding operations in North America by delivering remote access trojans (Remcos, NjRAT and others) via phishing emails that use password-protected RAR/BZ2 archives containing VBScript which launches Ande Loader; crypters and alternative delivery (Discord CDN) are observed, and related loader activity (DBatLoader) abusing a vulnerable driver to disable security tools is also noted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.