


Perceptive Security
SOC/SIEM Consultancy

Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER
Published:
27 maart 2026 om 00:00:00
Alert date:
26 maart 2026 om 19:02:42
Source:
elastic.co
Ransomware & Malware, Critical Infrastructure
Elastic Security Labs discovered two custom malware components targeting a South Asian financial institution. BRUSHWORM is a modular backdoor with USB-based spreading capabilities, while BRUSHLOGGER is a DLL-side-loaded keylogger. The attack specifically targets financial services in the South Asian region, demonstrating sophisticated techniques including USB propagation for lateral movement and DLL side-loading for persistence. This represents an active threat against critical financial infrastructure with potential for significant impact.
Technical details
Mitigation steps:
Affected products:
South Asian financial institution systems
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
