The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

OctLurk and SilkLurk: Analysis of a Modular Cyber Espionage Framework

Aug 6, 2026, 2:14:03 PM / by The Hivemind posted in Threat Bulletin, PlugX, credential theft, cyber espionage, OctLurk, SilkLurk, LurkProxy, modular backdoor

0 Comments

Verticals Targeted: Government, Ministries of Foreign Affairs, Healthcare, Research, Logistics, Law Enforcement, Urban Planning and Facilities Management, Education
Regions Targeted: Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, Uzbekistan
Related Families: OctLurk, SilkLurk, LurkProxy, PlugX

Executive Summary

Industry researchers have identified a sophisticated cyber espionage campaign leveraging two previously undocumented malware families, OctLurk and SilkLurk, against government organizations and public-sector entities across Central Asia and the Middle East. Both modular backdoors employ victim-specific decryption, extensive obfuscation, and in-memory execution to evade detection while enabling credential theft, remote access, network reconnaissance, and plugin-based expansion. Researchers also identified a companion utility, LurkProxy, used to proxy attacker traffic.

Read More

ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework

Aug 3, 2026, 1:59:52 PM / by The Hivemind posted in Threat Bulletin, Remcos RAT, ClickFix, UAT-11795, Cisco Talos, Starland RAT, WLDR, WLDR PowerShell, CastleStealer, Trojanized installers

0 Comments

Verticals Targeted: Cryptocurrency
Regions Targeted: United States, Germany, Romania, Venezuela
Related Families: Starland RAT, WLDR Framework, Remcos RAT, CastleStealer

Executive Summary

Industry researchers identified a financially motivated, Russian-speaking threat actor tracked as UAT-11795 conducting a sophisticated malware campaign targeting users primarily in the United States since at least June 2025. The operation employs suspected ClickFix-style social engineering, trojanized software installers, and a custom Python-based remote access tool, Starland RAT, to establish persistent access and deploy additional malware, including the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT. The campaign demonstrates a modular architecture, resilient C2 infrastructure, and a strong emphasis on credential theft, cryptocurrency wallet harvesting, and long-term post-compromise access.

Read More

Mirage Kitten Deploys NightLedger Backdoor in Espionage Campaign Targeting the Middle East and Africa

Jul 31, 2026, 1:58:15 PM / by The Hivemind posted in Threat Bulletin, Spear Phishing, Nimbus Manticore, cyber espionage, aerospace cybersecurity, UNC1549, Mirage Kitten, NightLedger, ArcBridge, Smoke Sandstorm, WebSocket tunneling, BridgeHead

0 Comments

Verticals Targeted: Aerospace, Aviation, Defense, Telecommunications, Government, Financial Services, SMBs
Regions Targeted: Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso
Related Threat Actors: Mirage Kitten
Related Families: NightLedger, BridgeHead, ArcBridge

Executive Summary

New research details the continued evolution of Mirage Kitten, an advanced persistent threat (APT) group conducting cyber-espionage operations across the Middle East and Africa. The campaign introduces three previously undocumented malware families, NightLedger, BridgeHead, and ArcBridge, that provide reconnaissance, command execution, covert tunneling, and persistent post-compromise access capabilities. The findings demonstrate Mirage Kitten's continued investment in bespoke malware development and operational security to support long-term intelligence collection.

Read More

Iranian PLC Exploitation Campaign Targets US Critical Infrastructure

Jul 27, 2026, 2:18:15 PM / by The Hivemind posted in Threat Bulletin, Iranian APT, ICS cybersecurity, PLC security, Rockwell Automation, Allen-Bradley, OT security, SCADA attack

0 Comments

Verticals Targeted: Government, Water, Energy, Critical Infrastructure
Regions Targeted: US

Read More

HOLLOWGRAPH: The New Face of Cloud-Based Espionage

Jul 24, 2026, 2:46:49 PM / by The Hivemind posted in Threat Bulletin, cyber espionage, cloud-native malware, Cavern framework, HOLLOWGRAPH, Microsoft Graph API malware, DNS tunneling, Microsoft 365 calendar malware

0 Comments

Regions Targeted: Israel
Related Families: HOLLOWGRAPH, Cavern Framework

 

Executive Summary

Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data. The campaign appears highly targeted, with at least 12 identified victims, primarily Israeli organizations, and only a small subset actively communicating with attacker infrastructure, suggesting a disciplined espionage operation.

Read More

CrashStealer: How Native macOS Malware Is Raising the Bar

Jul 20, 2026, 2:18:45 PM / by The Hivemind posted in Threat Bulletin, MacOS malware, macOS infostealer, Apple Keychain theft, browser credential theft, cryptocurrency wallet malware, CrashStealer, CrashStealer malware

0 Comments

Executive Summary

Industry researchers have identified CrashStealer, a newly active macOS infostealer that combines a signed and notarized delivery mechanism with sophisticated credential theft, cryptocurrency wallet targeting, and extensive anti-analysis techniques. Unlike many existing macOS stealers that rely on AppleScript or Objective-C wrappers, CrashStealer is implemented primarily in native C++, reflecting an increasingly mature approach to macOS malware development. The malware abuses trusted Apple technologies to bypass user protections, validates stolen credentials locally before collection, encrypts harvested data using AES-256-GCM, and establishes persistence through LaunchAgents while masquerading as legitimate Apple components. The campaign demonstrates that macOS ecosystems are no longer niche targets.

Read More

GigaWiper: Inside a Modular Cyberweapon

Jul 17, 2026, 2:51:19 PM / by The Hivemind posted in Threat Bulletin, modular malware, Microsoft threat intelligence, GigaWiper, BLUERABBIT, Crucio ransomware, Zebrocy, Golang malware, FlockWiper

0 Comments

Related Families: GigaWiper, Crucio, FlockWiper, Zebrocy

Executive Summary

Industry researchers identified GigaWiper, a sophisticated Golang-based malware platform that combines remote administration, persistence, reconnaissance, surveillance, and multiple destructive payloads within a single modular implant. Rather than deploying separate malware families for different objectives, the threat actor consolidated disk wiping, irreversible file encryption, secure data destruction, and extensive command-and-control (C2) functionality into one flexible backdoor.

Read More

BusySnake Stealer: Inside Armored Likho's AI-Assisted Malware Operation

Jul 13, 2026, 1:09:43 PM / by The Hivemind posted in Threat Bulletin, Infostealer, Spear Phishing, Python Malware, credential theft, Armored Likho, BusySnake Stealer, AI-assisted malware, Eagle Werewolf, reverse SSH tunnel

0 Comments

Verticals Targeted: Government, Electric, Energy, Critical Infrastructure
Regions Targeted: Russia, Kazakhstan, Brazil
Related Threat Actors: Armored Likho
Related Families: BusySnake

Executive Summary

Researchers have identified an active phishing campaign introducing a previously undocumented Python-based infostealer dubbed BusySnake Stealer. Targeting government agencies and electric power organizations across Russia, Kazakhstan, and Brazil, the campaign combines AI-assisted first-stage loaders, modular malware, GitHub-hosted payload delivery, and advanced credential theft capabilities. The operation demonstrates the group's continued technical evolution and highlights how increasingly modular malware can complicate traditional signature-based detection while reinforcing the importance of behavioral analytics and threat intelligence.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts