Pulling the Thread: Invite Only
ID: 20e5ea8b-33f9-530d-88da-51717c32fdad
STIX ID: report--20e5ea8b-33f9-530d-88da-51717c32fdad
Feed Name: Plausible Deniablility
Date Published: 2026-04-20
Date Updated: 2026-08-11
Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}
This report details an investigative analysis of a widespread phishing campaign using a reused invite.php template to impersonate conferencing apps and deliver malware (including a signed ZoomWorkspaceClientSetup.exe, SHA256: 5701dabd...c3faea). The analyst clusters domains by hosting and DNS SOA data, identifies an OPSEC link to an email ([email protected]) and a forum persona (eatingMemory) associated with Loominost hosting, and provides IoCs and retro-hunting guidance to detect the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
