Emerging Hacktivist Malware Threats in South Asia: A Critical Analysis
Recent hacktivist activities in South Asia have introduced sophisticated malware families, including polymorphic ransomware and fileless malware, posing critical threats to regional cybersecurity.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Hacktivist
- Geography:
- South Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In early 2026, South Asia has witnessed a surge in cyberattacks attributed to hacktivist groups targeting critical infrastructure and financial institutions. These attacks have introduced novel malware families, including polymorphic ransomware, rootkits, and fileless malware, necessitating an in-depth analysis of their characteristics and implications.
Emerging Malware Families
-
BRUSHWORM and BRUSHLOGGER: In March 2026, a South Asian financial institution was compromised by a custom malware toolkit comprising BRUSHWORM and BRUSHLOGGER. BRUSHWORM is a modular backdoor facilitating installation, persistence, and command-and-control (C2) operations, while BRUSHLOGGER functions as a DLL side-loaded keylogger, capturing keystrokes and user activity. The malware employs basic anti-analysis techniques, such as checking for sandbox environments and monitoring user activity before executing its payloads. It also infects removable drives with deceptive filenames to exfiltrate sensitive data. (cyware.com)
-
Osiris Ransomware: In November 2025, a new ransomware family named Osiris emerged, targeting a major Southeast Asian food service operator. Distinct from its 2016 namesake, this operation utilized a Bring Your Own Vulnerant Driver (BYOVD) attack with the malicious Poortry driver to disable defenses before encrypting files and exfiltrating data to Wasabi cloud storage. (cyware.com)
Advanced Malware Techniques
-
Polymorphic Ransomware: The integration of AI into cybercrime has led to the development of ransomware capable of mutating on the fly, making detection and mitigation more challenging. This evolution allows for rapid adaptation to security measures, enhancing the effectiveness of attacks. (itseller.us)
-
Fileless Malware: Hacktivist groups have increasingly employed fileless malware, which resides in memory and leverages legitimate system tools to execute malicious activities. This approach evades traditional detection methods that rely on file-based signatures. (malware.news)
Rootkits and C2 Infrastructure
Rootkits have been utilized to maintain persistent access to compromised systems, often operating at the kernel level to evade detection. Additionally, the establishment of robust C2 infrastructures, including the use of proxy servers and encrypted communication channels, has enabled attackers to control and exfiltrate data from compromised systems effectively. (ics-cert.kaspersky.com)
Conclusion
The landscape of cyber threats in South Asia has evolved significantly, with hacktivist groups deploying sophisticated malware families and advanced techniques. The emergence of polymorphic ransomware, fileless malware, and rootkits, coupled with the establishment of resilient C2 infrastructures, underscores the critical need for enhanced cybersecurity measures and proactive threat intelligence to mitigate these evolving risks.
Highlights:
- Cyware Daily Threat Intelligence, March 27, 2026, Published on Thursday, March 26
- Cyware Daily Threat Intelligence, January 23, 2026, Published on Thursday, January 22
- Ransomware 2026: an exponential leap driven by the integration of AI into cybercrime | ITseller US, Published on Tuesday, February 17
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware Attacks Triggers Massive Apple Security Alert Wave

New Pegasus Zero-Click Exploits Target Activists as Global Mercenary Spyware Campaigns Intensify

