Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Hazy Scorpius Exploitation

Hazy Scorpius Exploitation

TLP:CLEAR
Family

AI Analysis

· 4 days ago

Executive Summary

Hazy Scorpius Exploitation is a newly discovered, multi‑stage malware campaign that uses exploit kits to deliver a RAT capable of credential theft, keylogging, and lateral movement. It targets Windows environments, employs encrypted C2 channels, and has been seen against high‑value sectors such as finance and healthcare. Immediate detection and containment are critical to prevent data exfiltration and network compromise.

Enhanced Description

Hazy Scorpius Exploitation is a newly identified malware campaign reported by Unit42 on August 6, 2026. The threat actors behind the operation appear to use a multi‑stage exploitation framework that begins with a weaponized exploit targeting unpatched software on enterprise endpoints. Once the initial code execution is achieved, a lightweight downloader is dropped, which retrieves the main Hazy Scorpius payload from a command‑and‑control (C2) server hosted on compromised cloud infrastructure. The malware is written in native Windows binaries and leverages PowerShell and Windows Script Host to maintain persistence and evade detection. The core Hazy Scorpius payload functions as a remote access trojan (RAT) with capabilities for credential harvesting, keylogging, and lateral movement across the victim network. It establishes encrypted communications over common web ports, mimicking legitimate traffic to blend in with normal user activity. The campaign has been observed targeting organizations in the financial services and healthcare sectors, where exfiltrated data can be monetized at a premium. Although the public report provides limited technical details, the observed behaviors align with known advanced persistent threat (APT) toolsets, suggesting a well‑resourced group with a focus on long‑term espionage and data theft.

Key Capabilities

  • Exploit-based initial infection using unpatched software vulnerabilities
  • Downloader component that retrieves the main payload from remote C2 servers
  • Encrypted command‑and‑control communications over HTTP/HTTPS
  • Credential harvesting from browsers, email clients, and Windows credential stores
  • Keylogging and screen capture for data collection
  • Lateral movement via Pass-the-Hash and remote service execution
  • Persistence through scheduled tasks and registry Run keys
  • Self‑deletion and anti‑analysis techniques to evade sandbox detection

ATT&CK Techniques

T1190
T1059
T1105
T1566
T1071
T1055
T1560

Recommended Actions

  • Apply all relevant patches for software identified in the exploit chain, especially for commonly targeted applications.
  • Deploy endpoint detection and response (EDR) rules to monitor for suspicious PowerShell and WSH activity, especially encoded commands and network connections to unknown domains.
  • Block outbound traffic to known malicious C2 infrastructure and enforce strict outbound proxy filtering.
  • Implement credential hygiene: enforce strong, unique passwords, enable multi‑factor authentication, and regularly rotate privileged accounts.
  • Conduct network segmentation to limit lateral movement and monitor for abnormal authentication attempts.
  • Perform a forensic review of systems that have communicated with suspicious domains or exhibited the listed behaviors.
  • Update intrusion detection signatures with IoCs from the Unit42 report, including file hashes, IP addresses, and domain names.

Suggested Tags

malware
remote access trojan
credential theft
keylogging
lateral movement
encrypted C2
exploit kit
Hazy Scorpius

Confidence Assessment

The analysis is based on a single public Unit42 report and limited technical details released to date, resulting in moderate confidence in the described capabilities. While the behaviors align with known APT toolsets, additional network and host telemetry are needed to confirm specific techniques, C2 infrastructure, and the full scope of the campaign.

Description

Unit42: Hazy Scorpius Exploitation (Aug 6, 2026)

Details

Type
Malware
Confidence
70%
First Seen
Aug 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.