SoupDealer Malware Bypasses Every Sandbox, AV’s and EDR/XDR in Real-World Incidents

In early August 2025, cybersecurity teams in Türkiye observed a new, highly evasive Java‐based loader that slipped past every public sandbox, antivirus solution, and even enterprise EDR/XDR platforms. This threat—codenamed SoupDealer—surfaced as a phishing campaign distributing a three‐stage loader via files such as TEKLIFALINACAKURUNLER.jar. Deployed through targeted spearphishing, the initial .jar file only unpacks its […]

The post SoupDealer Malware Bypasses Every Sandbox, AV’s and EDR/XDR in Real-World Incidents appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: