A sophisticated modular loader utilizing multiple programming languages to evade detection has been discovered. The attack begins with Microsoft Teams phishing where attackers impersonate IT helpdesk personnel, convincing targets to install a fake PowerShell cleaner via MSI installer. The malware deploys memory-resident components bridging Python, C#, C++, and PowerShell to profile systems, establish persistence via scheduled tasks, and deploy a fake Windows lock screen to phish user credentials. Additional modules include a reverse proxy for network tunneling, enabling threat actors to access internal corporate systems using compromised credentials, plus remote shell and VNC capabilities for hands-on-keyboard attacks. The elaborate multi-stage infection chain suggests potential ransomware operations or initial access brokering.
Created: 2026-08-21
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。