BRUSHWORM is a custom modular Windows backdoor observed in a targeted intrusion against a financial institution in South Asia. It acts as the primary implant, establishing scheduled-task persistence, communicating with command-and-control infrastructure, downloading and executing additional DLL modules, collecting targeted files, and propagating through removable media. Its collection targets include documents, spreadsheets, presentations, archives, email stores, source code, and structured data files. When network connectivity is unavailable, BRUSHWORM can copy collected material to removable media, enabling physical exfiltration and movement of data from network-restricted or air-gapped environments. The backdoor uses socially engineered executable names on removable drives to encourage execution on additional Windows systems. It also performs basic anti-analysis checks involving display characteristics, host and user names, virtualization artifacts, and mouse activity. BRUSHWORM has been associated with BRUSHLOGGER, a separate DLL-side-loaded keylogger used in the same operation. The tooling exhibited signs of iterative development and comparatively low implementation sophistication; no threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
BRUSHWORM stores configuration fields encrypted with AES-CBC; BRUSHLOGGER XOR-encrypts keystroke logs using byte 0x43.
BRUSHWORM, disguised as paint.exe... BRUSHLOGGER, meanwhile, masqueraded as libcurl.dll, a commonly trusted Windows library... using socially engineered filenames like Salary Slips.exe, Documents.exe, and Dont Delete.exe
BRUSHLOGGER masquerades as libcurl.dll, and BRUSHWORM installs in hidden paths including C:\ProgramData\Photoes\Pics\ and C:\Users\Public\AppData\Roaming\Microsoft\Vault\.
BRUSHWORM... stealing sensitive documents from infected systems.
Two threads target external storage devices, including a thread that enumerates and steals files from connected removable and optical drives.
BRUSHWORM, disguised as paint.exe, acted as the primary implant — responsible for establishing persistence, communicating with a remote command-and-control (C2) server, downloading additional payloads...
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor used as the primary implant. It establishes persistence via scheduled tasks, communicates with a remote C2 server, downloads additional payloads, spreads through removable USB drives, and steals sensitive documents from infected systems. It can also copy stolen files to connected USB drives for exfiltration in offline environments.
A custom modular Windows backdoor that uses a scheduled task named MSGraphics for logon persistence, retrieves DLL payloads from its C2, and installs them through a second scheduled task. It performs basic sandbox checks, stores an AES-CBC configuration, propagates through USB devices using lure filenames, stages documents and other files for exfiltration, and can copy stolen data to USB media for physical exfiltration in offline or air-gapped environments.
Custom modular backdoor used as the primary implant. It establishes persistence via scheduled task, communicates with a C2 server, downloads DLL payloads, spreads through removable media, performs anti-analysis checks, and steals a broad range of files including documents, spreadsheets, email archives, and source code. It also supports offline USB-based exfiltration for restricted or air-gapped environments.
A custom modular backdoor with USB-based spreading observed targeting a South Asian financial institution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.