logo

Acronis TRU Alliance {VirusTotal}: Tracking FileFix, Shadow Vector, and SideWinder

ID: 9142d31a-1246-5c0d-b3b6-f5bdf61d2b34

STIX ID: report--9142d31a-1246-5c0d-b3b6-f5bdf61d2b34

Feed Name: TRU Security by Acronis

Threat Score
72/100

Date Published: 2025-11-10

Date Updated: 2026-07-24

...
...

Acronis Threat Research Unit (TRU), in collaboration with VirusTotal, presents practical threat-hunting case studies for three active campaigns: FileFix (a ClickFix web-based clipboard-driven PowerShell delivery), SideWinder (document-based attacks leveraging CVE-2017-0199 and CVE-2017-11882 targeting South Asia), and Shadow Vector (judicial-themed SVG lures targeting Colombia). The report explains how VirusTotal features (Livehunt, Retrohunt, VT Diff, content search, metadata filters) were used to create and refine YARA rules, recover IOCs and payload artifacts, and map infrastructure and delivery chains, and it supplies example YARA rules, hashes, and hunting guidance to reproduce and extend the detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.