ZipLine attack uses 'Contact Us' forms, White House butler pic to invade sensitive industries
ID: 196acb57-79b6-5228-85d4-67cbceb73399
STIX ID: report--196acb57-79b6-5228-85d4-67cbceb73399
Feed Name: The Register (Security)
Check Point disclosed the ZipLine campaign: a sophisticated phishing operation that uses organizations' public Contact Us forms and long-lived, previously legitimate domains to initiate contact, then delivers a ZIP archive containing a malicious LNK that runs an in-memory PowerShell implant (MixShell). MixShell establishes C2 via DNS TXT tunneling (with HTTP fallback), supports remote command/file ops and reverse-proxying for deeper network access, and is being used to enable data theft, ransomware extortion, and supply-chain disruption—dozens of organizations (primarily US manufacturers) were targeted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
