logo

Hackers use fake NDAs to deliver malware to US manufacturers

ID: 2c3b8940-e413-594c-8f96-44a424a63b97

STIX ID: report--2c3b8940-e413-594c-8f96-44a424a63b97

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-08-27

Date Updated: 2026-05-01

...
...

Researchers uncovered a targeted phishing campaign that abuses corporate 'Contact Us' forms to engage victims over days, then send ZIP archives hosted on Heroku containing custom malware called MixShell disguised as NDAs. The operation targets U.S. industrial, manufacturing, semiconductor, biotech, aerospace and other firms, uses long-established fake domains to evade filters, selectively serves malicious payloads based on victim attributes, and shows infrastructure overlap with a cluster (UNK_GreenSec) linked to Russia-aligned cybercriminal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.