Cybersecuritynews Emerging Threat: Kiss Loader Malware Exploits Early Bird APC Injection
Article Content
- •Kiss Loader uses Early Bird APC injection to stealthily infiltrate Windows systems.
- •The malware was first detected in early March 2026 and is still under active development.
- •It employs a multi-stage execution flow, including dynamic payload delivery via WebDAV.
A new malware loader named 'Kiss Loader' has been identified, utilizing advanced process injection techniques, specifically Early Bird APC injection, to infiltrate Windows systems. The malware was first spotted in early March 2026 and is still under active development, indicating a potential for future evolution into a more sophisticated attack tool. The infection vector begins with a Windows Internet Shortcut file that connects to a remote WebDAV resource, allowing the attacker to dynamically host payloads. Kiss Loader employs a multi-stage execution flow, including a JScript component that orchestrates the infection process and establishes persistence on the victim's system. The loader is capable of deploying additional payloads, including a variant of VenomRAT. Security analysts are closely monitoring this emerging threat as it poses significant risks to users and organizations alike.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…