ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)

A Highly Evasive Malware Campaign Targets Global Organizations with Sophisticated Tactics

A disturbing new wave of malware attacks has been detected sweeping across the globe, affecting organizations in various sectors and leaving security experts scratching their heads. The attackers’ arsenal is an amalgamation of cutting-edge techniques and tactics that have left traditional defenses struggling to keep up.

The malware campaign, which has already infected numerous high-profile targets worldwide, utilizes a combination of advanced evasion methods and exploit kits to infiltrate networks undetected. According to sources familiar with the investigation, the attackers are leveraging zero-day exploits for well-known vulnerabilities in popular software packages, while also employing sophisticated anti-detection techniques such as code obfuscation and sandbox evasion.

One of the most concerning aspects of this campaign is its use of living-off-the-land (LOTL) tactics. By leveraging legitimate system tools and binaries, the attackers are able to blend seamlessly into their victims’ networks, making it extremely challenging for security teams to detect and contain the malware. This approach also allows the attackers to bypass traditional signature-based detection methods, further complicating incident response efforts.

The scope of this campaign is broad, with organizations across various industries reporting infections. Financial services, healthcare, and government institutions have all been targeted, highlighting the potential for significant financial and reputational damage. The attackers appear to be after sensitive data, as well as access to high-value assets and systems, but the true motives behind this campaign remain unclear.

The effectiveness of these attacks underscores the need for organizations to reevaluate their security postures and adopt more proactive measures. This includes implementing robust monitoring and detection capabilities, regular vulnerability assessments, and employee education on the dangers of spear-phishing and other social engineering tactics. In particular, CISOs should focus on developing a deeper understanding of their networks’ vulnerabilities and developing incident response plans that account for these highly evasive malware attacks.

To stay ahead of this threat, it is essential to maintain a high level of situational awareness and keep security software up-to-date. Regularly review your network’s logs and system activity to detect any unusual behavior or unauthorized access attempts. By taking these proactive steps, organizations can significantly reduce their exposure to this highly sophisticated malware campaign and stay one step ahead of the attackers.


Source: SANS ISC — 2026-09-25