logo

Threat actors use copyright infringement phishing lure to deploy infostealers

ID: 5e482b97-13a3-567c-8b0d-d414424e02bc

STIX ID: report--5e482b97-13a3-567c-8b0d-d414424e02bc

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2024-10-31

Date Updated: 2026-04-27

Author: Joey Chen

...
...

Cisco Talos observed an ongoing phishing campaign targeting Facebook business/advertising users in Taiwan that uses copyright-infringement decoys and fake PDF filenames to trick victims into downloading password-protected RAR archives; those archives drop fake PDF executables which deploy LummaC2 and Rhadamanthys information stealers via Appspot/short-URL/Dropbox delivery, using heavy obfuscation, shellcode encryption, resource stuffing (>700 MB), persistence via registry/run keys and process injection, and multiple C2 domains—Talos provides analysis and associated IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.