{"id":9783,"date":"2026-01-10T10:03:47","date_gmt":"2026-01-10T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/10\/phishing-campaign-uses-maduro-arrest-story-to-deliver-backdoor-malware\/"},"modified":"2026-01-10T10:03:47","modified_gmt":"2026-01-10T10:03:47","slug":"phishing-campaign-uses-maduro-arrest-story-to-deliver-backdoor-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/10\/phishing-campaign-uses-maduro-arrest-story-to-deliver-backdoor-malware\/","title":{"rendered":"Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware"},"content":{"rendered":"<p>    Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals are leveraging the recent arrest of Venezuelan President Nicol\u00e1s Maduro to distribute sophisticated<a href=\"https:\/\/cybersecuritynews.com\/techniques-to-detect-outlook-notdoor\/\" target=\"_blank\" rel=\"noreferrer noopener\"> backdoor malware<\/a>. <\/p>\n<p>The threat actors exploited news surrounding Maduro\u2019s arrest on January 3, 2025, demonstrating how geopolitical events continue to serve as effective lures for malicious campaigns.<\/p>\n<p>The attack likely begins with a spear-phishing email containing a zip archive named \u201cUS now deciding what\u2019s next for Venezuela.zip\u201d. <\/p>\n<p>Inside, victims find an executable file titled \u201cMaduro to be taken to New York.exe\u201d alongside a malicious dynamic-link library called \u201ckugou.dll\u201d. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" height=\"233\" width=\"1024\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-39-1024x233.png?resize=1024%2C233&#038;ssl=1\" alt=\" DLL called with LoadLibraryW\" class=\"wp-image-174533\"><figcaption class=\"wp-element-caption\">\u00a0DLL called with LoadLibraryW<\/figcaption><\/figure>\n<p>The executable is a legitimate KuGou binary, but has been weaponized via DLL hijacking to load the malicious library, according to<a href=\"https:\/\/www.darktrace.com\/blog\/maduro-arrest-used-as-a-lure-to-deliver-backdoor\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> Darktrace security researchers<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-malware-behavior\"><strong>Malware Behavior<\/strong><\/h2>\n<p>Once executed, the malware creates a directory at C:ProgramDataTechnology360NB and copies itself, renaming the files. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" height=\"204\" width=\"1024\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-40-1024x204.png?resize=1024%2C204&#038;ssl=1\" alt=\" Folder \u201cTechnology360NB\u201d created\" class=\"wp-image-174536\"><figcaption class=\"wp-element-caption\">\u00a0Folder \u201cTechnology360NB\u201d created<\/figcaption><\/figure>\n<p>It establishes persistence by adding a registry key at \u201cHKCUSoftwareMicrosoftWindowsCurrentVersionRunLite360\u201d that runs automatically at system startup. <\/p>\n<p>The malware then displays a dialog box prompting users to restart their computer, which triggers the <a href=\"https:\/\/cybersecuritynews.com\/fvncbot-android-banking-attacking\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious payload<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-41.png?ssl=1\" alt=\"Message box prompting user to restart\" class=\"wp-image-174537\"><figcaption class=\"wp-element-caption\">Message box prompting user to restart<\/figcaption><\/figure>\n<\/div>\n<p>After the system restarts, the malware initiates regular <a href=\"https:\/\/cybersecuritynews.com\/quasarrat-core-functionalities-along-with-encrypted-configuration\/\" target=\"_blank\" rel=\"noreferrer noopener\">encrypted <\/a>connections to a command-and-control server at 172.81.60[.]97 on port 443. <\/p>\n<p>These periodic connections enable the malware to receive instructions and configurations from the attackers.<\/p>\n<p>The campaign shares similarities with previous operations by Mustang Panda, a Chinese threat group known for exploiting current events such as the Ukraine war, Tibet-related conventions, and Taiwan-related topics. <\/p>\n<p>However, researchers note that there is insufficient evidence to attribute this activity to any specific group definitively.<\/p>\n<p>This incident highlights the ongoing threat of geopolitical-themed <a href=\"https:\/\/cybersecuritynews.com\/malicious-svgs-in-phishing-campaigns-how-to-detect-hidden-redirects-and-payloads\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing campaigns<\/a>. <\/p>\n<p>Organizations and individuals should exercise extreme caution when opening email attachments, especially those referencing breaking news or world events.<\/p>\n<p><strong>Indicators of Compromise (IoCs)<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>172.81.60[.]97<\/li>\n<li>8f81ce8ca6cdbc7d7eb10f4da5f470c6 \u2013 US now deciding what\u2019s next for Venezuela.zip<\/li>\n<li>722bcd4b14aac3395f8a073050b9a578 \u2013 Maduro to be taken to New York.exe<\/li>\n<li>aea6f6edbbbb0ab0f22568dcb503d731 \u00a0\u2013 kugou.dll<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/phishing-campaign-uses-maduro-arrest-deliver-malware\/\">Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/phishing-campaign-uses-maduro-arrest-deliver-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware Cybercriminals are leveraging the recent arrest of Venezuelan President Nicol\u00e1s Maduro to distribute sophisticated backdoor malware. The threat actors exploited news surrounding Maduro\u2019s arrest on January 3, 2025, demonstrating how geopolitical events continue to serve as effective lures for malicious campaigns. The attack likely begins [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258,131],"tags":[130],"class_list":["post-9783","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9783"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9783"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9783\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}