logo

Stealthy BLOODALCHEMY Malware Targeting ASEAN Government Networks

ID: 913aee56-8fc4-59be-b1ef-b7659bb57b0f

STIX ID: report--913aee56-8fc4-59be-b1ef-b7659bb57b0f

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-05-24

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers report that BLOODALCHEMY is an updated Deed RAT/ShadowPad‑related backdoor used in espionage campaigns targeting government organizations in Southern and Southeastern Asia; it employs DLL side‑loading (BrDifxapi.exe/BrLogAPI.dll), in‑memory shellcode extracted from DIFX files, and run‑modes to evade analysis and manage persistence, and its code overlaps suggest reuse of centralized tooling among China‑linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.