Emerging Hacktivist Malware Threats in North America: Advanced Analysis
Hacktivist groups in North America are deploying sophisticated malware, including polymorphic ransomware, rootkits, and fileless malware, posing significant cybersecurity challenges.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- High
- Actor Type:
- Hacktivist
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
Hacktivist groups in North America are increasingly leveraging advanced malware techniques to disrupt critical infrastructure and gain unauthorized access to sensitive information. This briefing provides an in-depth analysis of novel malware families, reverse engineering findings, and command-and-control (C2) infrastructure associated with these threat actors.
Introduction
The landscape of cyber threats has evolved significantly, with hacktivist groups adopting more sophisticated malware to achieve their objectives. These groups often target critical sectors, including healthcare, energy, and government, aiming to cause disruption and draw attention to their causes.
Novel Malware Families and Reverse Engineering Findings
Polymorphic Ransomware: "EvilAI"
"EvilAI" is a polymorphic ransomware strain identified in late 2025. It employs advanced obfuscation techniques to evade detection by traditional security measures. Key characteristics include:
-
Dynamic Payload Generation: Utilizes MurmurHash3 32-bit hashing to create unpredictable control flow conditions, generating loops that appear potentially infinite to static analysis tools.
-
Evasion Techniques: Executes a JavaScript payload via Node.js, making the malware appear legitimate at every level. It also employs anti-analysis techniques to hinder reverse engineering efforts.
-
Persistence Mechanisms: Establishes persistence by creating scheduled tasks disguised as legitimate Windows processes and maintains autonomous communication with the C2 server. (ics-cert.kaspersky.com)
Fileless Malware: "PhaseBot"
"PhaseBot" is a fileless rootkit that operates entirely in memory, leaving minimal traces on disk. Its features include:
-
In-Memory Execution: Executes malicious code directly in the system's memory, avoiding detection by traditional file-based security solutions.
-
Rootkit Capabilities: Provides deep system access, allowing attackers to manipulate system processes and evade detection.
-
Persistence: Maintains persistence by exploiting system vulnerabilities and leveraging legitimate system processes. (link.springer.com)
Command-and-Control Infrastructure Analysis
Hacktivist groups have demonstrated innovative approaches to establishing and maintaining C2 infrastructure:
-
Use of Legitimate Services: Deploying remote monitoring and management (RMM) platforms, such as ATERA Networks, to install tools like AnyDesk, facilitating remote access and control. (ics-cert.kaspersky.com)
-
Abuse of Legitimate Tools: Utilizing services like Splashtop Remote's management service (SRManager.exe) to execute malware binaries, including those designed for different operating systems, to evade detection. (ics-cert.kaspersky.com)
Implications for North American Organizations
The adoption of these advanced malware techniques by hacktivist groups poses significant risks to North American organizations:
-
Increased Detection Challenges: Traditional security measures may struggle to detect polymorphic and fileless malware, necessitating the adoption of advanced detection and response strategies.
-
Potential for Widespread Disruption: Targeting critical infrastructure sectors can lead to significant operational disruptions and financial losses.
Recommendations
Organizations should consider the following measures to enhance their cybersecurity posture:
-
Implement Advanced Detection Tools: Utilize behavioral analysis and machine learning-based solutions to detect sophisticated malware variants.
-
Regularly Update and Patch Systems: Ensure all systems are up-to-date to mitigate vulnerabilities that could be exploited by malware.
-
Conduct Comprehensive Security Audits: Regularly assess security measures and incident response plans to identify and address potential weaknesses.
Conclusion
Hacktivist groups in North America are increasingly employing advanced malware techniques, including polymorphic ransomware, rootkits, and fileless malware, to achieve their objectives. Organizations must remain vigilant and proactive in adopting advanced security measures to mitigate these evolving threats.
Sources
-
Kaspersky ICS CERT. (2026). APT and financial attacks on industrial organizations in Q4 2025. (ics-cert.kaspersky.com)
-
Springer Nature. (2019). An emerging threat Fileless malware: a survey and research challenges. (link.springer.com)
-
Kaspersky ICS CERT. (2025). APT and financial attacks on industrial organizations in Q3 2025. (ics-cert.kaspersky.com)
-
MDPI. (2024). A Deep Learning Framework for Enhanced Detection of Polymorphic Ransomware. (mdpi.com)
-
PMC. (2023). Enhancing Cyber-Resilience for Small and Medium-Sized Organizations with Prescriptive Malware Analysis, Detection and Response. (pmc.ncbi.nlm.nih.gov)
-
InventiveHQ. (2024). Malware Analysis & Reverse Engineering: A Comprehensive Toolkit Workflow. (inventivehq.com)
Highlights:
- APT and financial attacks on industrial organizations in Q4 2025 | Kaspersky ICS CERT, Published on Thursday, March 05
- APT and financial attacks on industrial organizations in Q3 2025 | Kaspersky ICS CERT, Published on Sunday, November 30
- A Deep Learning Framework for Enhanced Detection of Polymorphic Ransomware | MDPI, Published on Thursday, July 17
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware Alerts: Apple Warns Users Across 110 Countries

Apple Issues Global Wave of Mercenary Spyware Alerts Amid Escalating Surveillance Threats

