cognitive cybersecurity intelligence

News and Analysis

Search

New KoiLoader Abuses Powershell Scripts to Deliver Malicious Payload

Researchers have uncovered a new strain of the advanced KoiLoader malware, believed to be distributed through phishing emails posing as bank statements. The malware employs PowerShell scripts in Windows shortcut files to evade conventional security detection. It carries the Koi Stealer virus, capable of stealing sensitive information. Experts advise disabling wscript.exe via AppLocker, closely monitoring PowerShell execution logs, and deploying behaviour-based detection tools to counter these types of threats.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts