HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures
A custom HVNC backdoor is targeting Latin American financial organizations via fake DocuSign and NFe tax-document lures, giving attackers hidden persistent remote access.
ANY.RUN researchers analyzed a multi-stage phishing campaign delivering a custom HVNC backdoor to banking and financial organizations in Latin America. The chain starts with fake DocuSign and NFe tax-document pages that serve per-visitor ZIP archives, followed by an LNK dropper, an NSIS loader, and a 64-bit backdoor masquerading as Windows Update Assistant. The implant provides hidden remote desktop control, keystroke monitoring, Firefox data theft, Startup-folder persistence, and EDR-aware behavior, communicating over TCP/27015.
Malware Crypting Services and the Threat Actors Who Sell Them
Recorded Future's Insikt Group profiles 24 threat actors selling malware crypting services and urges defenders to favor behavioral detection over static analysis.
Recorded Future's Insikt Group analyzed 24 threat actors that sell malware crypting services. The report covers their evasion techniques and the market dynamics of crypting-as-a-service. Insikt recommends that defenders prioritize behavioral detection over static analysis because crypting regularly alters malware file characteristics.