logo

ZipLine attack uses 'Contact Us' forms, White House butler pic to invade sensitive industries

ID: 196acb57-79b6-5228-85d4-67cbceb73399

STIX ID: report--196acb57-79b6-5228-85d4-67cbceb73399

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-08-26

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point disclosed the ZipLine campaign: a sophisticated phishing operation that uses organizations' public Contact Us forms and long-lived, previously legitimate domains to initiate contact, then delivers a ZIP archive containing a malicious LNK that runs an in-memory PowerShell implant (MixShell). MixShell establishes C2 via DNS TXT tunneling (with HTTP fallback), supports remote command/file ops and reverse-proxying for deeper network access, and is being used to enable data theft, ransomware extortion, and supply-chain disruption—dozens of organizations (primarily US manufacturers) were targeted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.