Unfurling Hemlock: The Malware Cluster Bomb Wreaking Havoc on PCs

Unfurling Hemlock has turned malware distribution into a “cluster bomb” spectacle, infecting systems with up to ten malicious payloads. Security firm KrakenLabs uncovered this chaotic strategy, which has been active since February 2023, targeting mainly the U.S., Germany, Russia, Turkey, India, and Canada.

Hot Take:

Unfurling Hemlock’s malware cluster bomb is like a cybercriminal’s version of a piñata, except you get malware instead of candy. But hey, at least they’re thorough!

Key Points:

  • Unfurling Hemlock infects systems with up to ten pieces of malware simultaneously.
  • Infection method involves a file named ‘WEXTRACT.EXE’ which unpacks multiple malware stages.
  • Malware types include information stealers, botnets, backdoors, and utilities to disable security features.
  • Over half of the attacks target systems in the United States.
  • KrakenLabs believes Unfurling Hemlock is based in Eastern Europe.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here