STASHLOG
- First seen
- 2022-09-15 00:00:00
- Malware type
- loader, dropper
- Profile updated
- 2026-07-07 15:16:19
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:us country_code:uk
Context
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
Reports & references
- twitter.com — 1433819369784610828 (report)
- cybereason.com — Operation Cuckoobees Deep Dive Into Stealthy Winnti Techniques (report)
- Mandiant — Unknown Actor Using Clfs Log Files For Stealth (report)
- cybereason.com — Operation Cuckoobees A Winnti Malware Arsenal Deep Dive (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Stashlog (report)