Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New PassiveNeuron Attacking Servers of High-Profile Organizations to Implant Malware

The PassiveNeuron cyberespionage campaign has re-emerged, targeting government, financial, and industrial organizations in Asia, Africa, and Latin America. Initially detected in 2024, the campaign resumed activity in December 2024, with recent infections…

The PassiveNeuron cyberespionage campaign has re-emerged, targeting government, financial, and industrial organizations in Asia, Africa, and Latin America. Initially detected in 2024, the campaign resumed activity in December 2024, with recent infections noted as of August 2025.

This campaign employs advanced persistent threat implants named Neursite and NeuralExecutor, along with the Cobalt Strike framework, to compromise Windows Server systems. It primarily targets Microsoft SQL servers to gain initial remote command execution, utilizing SQL vulnerabilities, injection flaws, or compromised database credentials. Attackers deploy ASPX web shells for sustained access, although security solutions often block these attempts.

To bypass detection, attackers use Base64 and hexadecimal encoding, switch between PowerShell and VBS scripts, and write payloads line-by-line. Researchers from Securelist have identified a sophisticated multi-stage infection chain involving DLL loaders.

The first-stage loaders are strategically placed in the System32 directory and exploit the Phantom DLL Hijacking technique for automatic persistence. These DLLs are artificially inflated to exceed 100 MB, making them difficult for security solutions to detect.

The PassiveNeuron cyberespionage campaign has re-emerged, targeting government, financial, and industrial organizations in Asia, Africa, and Latin America.
Olivia Harper · Thehackingpost

Advanced anti-analysis mechanisms, including MAC address validation, ensure execution only on intended victim machines. The first-stage loader exits immediately if no match is found, preventing execution in sandbox environments.

The PassiveNeuron infection chain follows a four-stage loading process. After the first-stage loader validates the target machine, it loads a second-stage DLL from disk, with file sizes exceeding 60 MB. This loader opens a text file containing Base64-encoded and AES-encrypted data with the third-stage loader. The third-stage payload launches a fourth-stage shellcode loader within legitimate processes like WmiPrvSE.exe or msiexec.exe.

Advertisement

The Neursite backdoor, as the final-stage implant, features modular capabilities for system reconnaissance, process management, lateral movement, and file operations. Attribution analysis suggests the involvement of Chinese-speaking threat actors, with techniques associated with APT31, APT27, and potentially APT41 groups.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories