logo

BlackSanta Report

ID: 6346750f-7d88-429e-8082-556e70fc8d12

STIX ID: report--6346750f-7d88-429e-8082-556e70fc8d12

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2026-02-25

Last Modified Date: 2026-02-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Aryaka Threat Labs describes a sophisticated, Russian‑language campaign targeting HR and recruitment personnel using resume-themed spear‑phishing (ISO with malicious LNK) that runs an obfuscated PowerShell loader (LSB steganography) to sideload a malicious DWrite.dll. The DLL beacons to C2 to retrieve AES keys for runtime decryption, downloads additional payloads (including an EDR‑killer called BlackSanta), leverages vulnerable kernel drivers to neutralize AV/EDR and perform stealthy process termination and process hollowing, and is capable of exfiltration; the report includes IOCs, infrastructure pivots, and MITRE ATT&CK mappings.