[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMSjB8BP5Bciy6h5Ok8cSRWm1BLb-PlfIj-7JuNd1m8s":3},{"article":4,"iocs":46,"watch_terms":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":26,"category":27,"article_tags":30},"55a01be9-4ad7-4fbd-9a21-aed32b2a7fd6","\"Salary Slips.exe.\" \"Dont Delete.exe.\" \"Important.exe.\"\n\nThese are the filenames BRUSHWORM copies...","salary-slips-exe-dont-delete-exe-important-exe-these-are-the-filenames-brushworm","\"Salary Slips.exe.\" \"Dont Delete.exe.\" \"Important.exe.\"\n\nThese are the filenames BRUSHWORM copies itself as when spreading across USB drives in a targeted attack on a South Asian financial institution.\n\nElastic Security Labs uncovered two custom components working together: a","Elastic Security Labs discovered BRUSHWORM, a malware campaign targeting a South Asian financial institution. The threat uses custom components that masquerade as legitimate files (Salary Slips.exe, Dont Delete.exe, Important.exe) when spreading across USB drives. The attack demonstrates a blend of social engineering and technical sophistication, combining multiple malicious components for network infiltration.","BRUSHWORM malware spreads via USB drives using deceptive filenames targeting South Asian financial institutions.",null,"https:\u002F\u002Fx.com\u002Felasticseclabs\u002Fstatus\u002F2040459383549637106","2026-04-04T16:00:01+00:00","2026-04-04T17:00:15.227335+00:00",8,[17,20,23],{"name":18,"type":19},"BRUSHWORM","threat_actor",{"name":21,"type":22},"Elastic","vendor",{"name":24,"type":25},"USB-based distribution","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":26,"icon":11,"name":28,"slug":29},"Malware","malware",[31,36,41],{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":42},{"id":43,"icon":11,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[47],{"type":29,"value":18,"context":48},"Custom malware campaign targeting South Asian financial institution via USB-based distribution",[21]]