Skip to content
Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks

Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks

Gbhackers •Mayura Kathir • March 27, 2026

A South Asian financial institution has been hit by a custom malware toolkit combining a modular backdoor, dubbed BRUSHWORM, and a DLL side‑loaded keylogger known as BRUSHLOGGER.  The attackers relied on a backdoor initially named paint.exe and a keylogger masquerading as libcurl.dll, both of which lacked advanced packing or obfuscation. BRUSHWORM acts as the primary implant, handling […]

Extracted Entities

Attack Types (1)

Industries (1)