• Skip to primary navigation
  • Skip to main content
  • Skip to footer
lab52

lab52

The threat intelligence division of S2 Grupo

  • Home
  • Faq
  • Blog
  • About
  • Contact

3722304989

Grandoreiro Stealer Targeting Spain and Latin America: Malware Analysis and Decryption Insights

April 04, 2025

A new campaign targeting Spain and Latin American countries, utilizing the Brazilian stealer Grandoreiro, was detected during March 2025. This report provides detailed insights into the malware’s behavior, along with an explanation of the string obfuscation and decryption techniques employed in this campaign. Grandoreiro Grandoreiro is a Brazilian-origin stealer malware that has been active since […]

3722304989

Mustang Panda’s PlugX new variant targetting Taiwanese government and diplomats

December 11, 2023

The Lab52 team has analysed a cyber campaign in which attackers deploy a new variant of the PlugX malware. Both the infection chain and the various artefacts used in the cyberattack share multiple similarities with the SmugX campaign, attributed to threat actors Red Delta and Mustang Panda, allegedly linked to the Chinese government. This time, […]

3722304989

GuLoader as the Gatekeeper of AgentTesla: A Comprehensive Analysis

May 22, 2023

The malware team at Lab52 has a saying that our colleages know well: “We want your malware”. On this occasion, the Theat Intelligence team gifted us a file that appeared to be a dropper. The file was already flagged by 15 antivirus engines on VirusTotal as malicious. Among the open files, the results of specific […]

3722304989

Let’s talk about the malware used by Mustang Panda

May 05, 2023

In the last post, Lab52 covered the new Mustang Panda’s campaing against Australia.  Now is time to talk about the malware used by the APT group Mustang Panda in said campaing.  Indeed, the malware used to commit the attack is not enterely new; there are previous reports from TrendMicro and Talos where similar tactics and […]

3722304989

Footer

Copyright &copy Lab52 2019 by S2 Grupo | Legal notice | Cookie policy | Privacy policy