Check out my research on unpacking a recent #ColibriLoader campaign along with some #YARA rules to detect it 🐦 https://www.bitsight.com/blog/unpacking-colibri-loader-russian-apt-linked-campaign
Unpacking Colibri Loader: A Russian APT linked Campaign | Bitsight

In this research, we present how to manually “unpack” a sample from a recent ColibriLoader malware campaign being distributed by PrivateLoader.