BRUSHWORM and BRUSHLOGGER uncovered

A South Asian financial institution was targeted with two custom malware components: BRUSHWORM, a modular backdoor, and BRUSHLOGGER, a keylogger. BRUSHWORM features anti-analysis checks, encrypted configuration, scheduled task persistence, modular payload downloading, USB worm propagation, and extensive file theft. BRUSHLOGGER uses DLL side-loading to capture system-wide keystrokes with window context tracking. The malware's low sophistication and implementation flaws suggest an inexperienced author, possibly using AI code-generation tools. Multiple testing versions were discovered on VirusTotal, indicating iterative development. The malware components combine to create a functional collection platform with modular loading, USB propagation, broad file theft, air-gap bridging, and persistent keystroke capture.

Pulse ID: 69c643be1c9656febe1f3cc6
Pulse Link: https://otx.alienvault.com/pulse/69c643be1c9656febe1f3cc6
Pulse Author: AlienVault
Created: 2026-03-27 08:45:50

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AWS #Asia #BackDoor #CyberSecurity #InfoSec #KeyLogger #Malware #OTX #OpenThreatExchange #RAT #Rust #SouthAsia #USB #VirusTotal #Worm #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

VirusTotal's Cloudflare relationship isn't incidental — it's structural. Every file you submit potentially enters a big-tech data graph. When your threat intelligence platform IS your surveillance infrastructure, the dependencies matter.

The agent tracks these supply-chain relationships as part of autonomous agent security monitoring. Privacy-first scanning at the-service.live/scrub?ref=mastodon-cloudflare

#InfoSec #Privacy #BigTech #VirusTotal

Virenjagd: VirusTotal flexibler nutzen per Kommandozeile | heise online heise.de/-11176057 #Antivirus #VirusTotal #Malware #vtcli

Virenjagd: VirusTotal flexible...
Virenjagd: VirusTotal flexibler nutzen per Kommandozeile

Batch-Scans mehrerer verdächtiger Dateien und passgenaue Malware-Recherchen zur Incident Response: Mit dem Gratis-Tool vt-cli folgt VirusTotal Ihrem Kommando.

Security
Virenjagd: VirusTotal flexibler nutzen per Kommandozeile | heise online
https://heise.de/-11176057 #Antivirus #VirusTotal #Malware #vtcli

Using DuckDuck Go as my main search engine for a while now.

My experience so far has been underwhelming. I get prompted the Ai generated result, and then I get a bunch of random websites that have very little information or are unreliable of what I am looking for. Just now when searching for VirusTotal, I got a search result of a malicious phishing site. I quickly got out, cleared my cookies, updated my browser, just to be safe. I will be searching for a new engine.
#DuckDuckGo #VirusTotal

Wow, now I'm getting malware URLs via reverb.com - way to hand over a long-time threat intel person the IoC's

nothing on VT yet https://www.virustotal.com/gui/url/3086617690b3b089bff0dd7b96f0e389a57ad32630fd93b6a29d6cdc8256edfe/detection
Zero detections:
https://www.urlvoid.com/scan/matyshkazemlya.com/
scan failed 403 forbidden: https://sitecheck.sucuri.net/results/www.matyshkazemlya.com

https://urlquery.net/report/7840c1b4-791d-47d1-b531-4ac3b7fd0f92 redirect and is sinkholed via DNS4EU
Submitted to Pulsedive: https://pulsedive.com/indicator/?ioc=d3d3Lm1hdHlzaGthemVtbHlhLmNvbQ==

Showing a redirect to Google on checkphish (LOL)
https://app.checkphish.ai/public/insights/1772914041531/3086617690b3b089bff0dd7b96f0e389a57ad32630fd93b6a29d6cdc8256edfe

IoC:
www.matyshkazemlya [DOT] com

Message on Reverb.com:
Hey, I've been trying to buy your listing but keep getting a payment error. The site gave me a link with some info for the seller to check — www.matyshkazemlya [DOT] com Could you take a look? Mia Brown

#IR #incidentRespose #CTI #IOC #infosec #cyberz #cybersecurity #infosec #reverb
#suspectdomain #virustotal #pulsedive #URLvoid #threatIntel #ThreatInteligence

VirusTotal

VirusTotal

Virenjagd: VirusTotal flexibler nutzen per Kommandozeile

Batch-Scans mehrerer verdächtiger Dateien und passgenaue Malware-Recherchen zur Incident Response: Mit dem Gratis-Tool vt-cli folgt VirusTotal Ihrem Kommando.

Security
Ah, yes, because the world was just crying out for a "skill marketplace" with built-in #malware scanning 😂. Clearly, the 2026 tech landscape needed a platform called "ClawHub" to lead the charge on #cybersecurity 🦾. After all, why bother with real security when you can just slap on a #VirusTotal sticker and call it a day? 🙄🔍
https://openclaw.ai/blog/virustotal-partnership #skillmarketplace #ClawHub #HackerNews #ngated
OpenClaw — Personal AI Assistant

OpenClaw — The AI that actually does things. Your personal assistant on any platform.

OpenClaw — Personal AI Assistant

OpenClaw — The AI that actually does things. Your personal assistant on any platform.

Could it be that that #heuristics for that detection is actually detecting the fucking #MSEdge updater, Google Chrome updater, UI0Detect, and WerFault instead?

The #VirusTotal Sandboxes are still quite noisy, aren't they?

#infosec