Campaigns aimed at stealing private information and gaining enduring remote access to infected computers have targeted governmental agencies, military organizations, and civilian users in Ukraine and Poland.
The incursion set, which spans the months between April 2022 and July 2023, uses phishing lures and fake documents to launch PicassoLoader, a downloader virus that serves as a conduit for Cobalt Strike Beacon and njRAT.
According to a recent analysis by Cisco Talos researcher Vanja Svajcer, “the attacks used a multistage infection chain initiated with malicious Microsoft Office documents, most frequently using Microsoft Excel and PowerPoint file formats.” This was followed by an executable downloader and payload that was hidden inside an image file read more PicassoLoader Malware Used in Ongoing Attacks on Ukraine and Poland.
Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and solutions.
