A sophisticated malware family leveraging Microsoft Outlook for communication via the Microsoft Graph API has been discovered, comprising a custom loader (PATHLOADER) and a backdoor (FINALDRAFT). PATHLOADER downloads encrypted shellcode and evades detection through encryption and obfuscation, while FINALDRAFT focuses on data exfiltration and process injection. Organizations must enhance security measures and monitor API use to combat these threats.
![](https://healsecurity.com/wp-content/uploads/2025/02/dn5tow9yger7cekyqevwba-1200-80.jpg)
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
Researchers from SecurityScorecard have discovered a Lazarus Group campaign targeting software and Web3 developers with concealed malware. The malware, known as Marstech1 and hidden within