BlackSanta Report
ID: 6346750f-7d88-429e-8082-556e70fc8d12
STIX ID: report--6346750f-7d88-429e-8082-556e70fc8d12
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2026-02-25
Last Modified Date: 2026-02-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Aryaka Threat Labs describes a sophisticated, Russian‑language campaign targeting HR and recruitment personnel using resume-themed spear‑phishing (ISO with malicious LNK) that runs an obfuscated PowerShell loader (LSB steganography) to sideload a malicious DWrite.dll. The DLL beacons to C2 to retrieve AES keys for runtime decryption, downloads additional payloads (including an EDR‑killer called BlackSanta), leverages vulnerable kernel drivers to neutralize AV/EDR and perform stealthy process termination and process hollowing, and is capable of exfiltration; the report includes IOCs, infrastructure pivots, and MITRE ATT&CK mappings.
