STASHLOG

First seen
2022-09-15 00:00:00
Malware type
loader, dropper
Profile updated
2026-07-07 15:16:19

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:uk

Context

Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.

Reports & references

  • twitter.com — 1433819369784610828 (report)
  • cybereason.com — Operation Cuckoobees Deep Dive Into Stealthy Winnti Techniques (report)
  • Mandiant — Unknown Actor Using Clfs Log Files For Stealth (report)
  • cybereason.com — Operation Cuckoobees A Winnti Malware Arsenal Deep Dive (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Stashlog (report)

External references