Threat hunters have uncovered a sophisticated malware campaign, attributed to REF7707, targeting a South American foreign ministry, a telecommunications firm, and a university in Southeast Asia. The malware, named FINALDRAFT, is a complex remote administration tool that can execute modules and uses the Outlook email service for command-and-control. Researchers believe the malware’s complexity suggests a well-organized group and likely an espionage-oriented campaign.
![](https://healsecurity.com/wp-content/uploads/2025/02/dn5tow9yger7cekyqevwba-1200-80.jpg)
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
Researchers from SecurityScorecard have discovered a Lazarus Group campaign targeting software and Web3 developers with concealed malware. The malware, known as Marstech1 and hidden within