#SuperBear
Malware/Tool
SuperBear is a Windows implant used in targeted phishing against civil-society groups, activists, and a journalist covering Asian geopolitics. A malicious LNK launched hidden PowerShell, opened a decoy DOCX, and obtained an AutoIt script that hollowed explorer.exe and injected the payload. SuperBear derives closely from the open-source Chimera Loader and combines loader behavior with remote-access functions. It creates a named mutex, validates command-and-control responses with an “NdBrldr” marker, collects process and system information, executes downloaded shell commands, and downloads and runs DLLs. Its code lineage explains why some researchers describe it as a dropper rather than a conventional RAT.
-
4
Tagged Reports
-
4
Unique Authors
-
16
Active Days