Direct-Sys Loader and CGrabber Stealer Five-Stage Malware Chain

Reported 17 Apr 2026 by otx · Severity: medium

A sophisticated five-stage malware operation delivers two new malware families: Direct-Sys Loader and CGrabber Stealer. The attack begins with ZIP archives distributed via GitHub user attachment URLs, exploiting a legitimate Microsoft-signed binary (Launcher_x64.exe) for DLL side