Skip to content
Cyberattack on South Asian Financial Firm Using BRUSHWORM and BRUSHLOGGER Malware

Cyberattack on South Asian Financial Firm Using BRUSHWORM and BRUSHLOGGER Malware

First seen 27 Mar 2026, 13:18 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 28, 2026 at 13:00 UTC

A South Asian financial institution has been targeted by a cyberattack utilizing two custom malware tools: BRUSHWORM, a modular backdoor, and BRUSHLOGGER, a keylogger disguised as a trusted system file. The attack involved file theft and real-time keystroke capture, indicating a sophisticated approach to data exfiltration. The malware was deployed through a backdoor named paint.exe and a keylogger masquerading as libcurl.dll, both of which did not employ advanced packing or obfuscation techniques. This incident highlights the increasing risks faced by financial organizations in the region. The specific impact on the institution's operations and data integrity remains unclear. As of now, there are no reports of a patch or mitigation strategy being implemented. The attack underscores the need for enhanced cybersecurity measures in the financial sector.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

Timeline

2026-03-27
Cyberattack reported on South Asian financial firm using BRUSHWORM and BRUSHLOGGER.

More articles in this cluster (2)

Following this threat?

Track Brushlogger in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed