Executive Summary
Hazy Scorpius Exploitation is a newly discovered, multi‑stage malware campaign that uses exploit kits to deliver a RAT capable of credential theft, keylogging, and lateral movement. It targets Windows environments, employs encrypted C2 channels, and has been seen against high‑value sectors such as finance and healthcare. Immediate detection and containment are critical to prevent data exfiltration and network compromise.
Enhanced Description
Hazy Scorpius Exploitation is a newly identified malware campaign reported by Unit42 on August 6, 2026. The threat actors behind the operation appear to use a multi‑stage exploitation framework that begins with a weaponized exploit targeting unpatched software on enterprise endpoints. Once the initial code execution is achieved, a lightweight downloader is dropped, which retrieves the main Hazy Scorpius payload from a command‑and‑control (C2) server hosted on compromised cloud infrastructure. The malware is written in native Windows binaries and leverages PowerShell and Windows Script Host to maintain persistence and evade detection. The core Hazy Scorpius payload functions as a remote access trojan (RAT) with capabilities for credential harvesting, keylogging, and lateral movement across the victim network. It establishes encrypted communications over common web ports, mimicking legitimate traffic to blend in with normal user activity. The campaign has been observed targeting organizations in the financial services and healthcare sectors, where exfiltrated data can be monetized at a premium. Although the public report provides limited technical details, the observed behaviors align with known advanced persistent threat (APT) toolsets, suggesting a well‑resourced group with a focus on long‑term espionage and data theft.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on a single public Unit42 report and limited technical details released to date, resulting in moderate confidence in the described capabilities. While the behaviors align with known APT toolsets, additional network and host telemetry are needed to confirm specific techniques, C2 infrastructure, and the full scope of the campaign.
Unit42: Hazy Scorpius Exploitation (Aug 6, 2026)