Hackers Leveraging CHM Files To Attack Users With Password-Protected Zip Files
ID: 438fcd2e-961f-5ad4-aed9-be8dda2f1356
STIX ID: report--438fcd2e-961f-5ad4-aed9-be8dda2f1356
Feed Name: cybersecurityNews.com
Securonix researchers identified the PHANTOM#SPIKE campaign using password-protected ZIPs and malicious CHM files masquerading as military-themed documents to drop a C# backdoor (RuntimeIndexer.exe). The CHM contains embedded JavaScript/OBJECT tags that trigger execution of a hidden EXE when interacted with; the backdoor performs network communication to a C2 for remote commands. The campaign appears politically motivated, targets Pakistan-associated victims (with some Western targets), and highlights a trend of abusing trusted file formats to bypass defenses; the report includes detection and mitigation recommendations such as endpoint logging and careful handling of unsolicited files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
