logo

PowMix botnet targets Czech workforce

ID: f76d1f16-9653-5989-be26-e957a58f1426

STIX ID: report--f76d1f16-9653-5989-be26-e957a58f1426

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-27

Author: Chetan Raghuprasad

...
...

Cisco Talos reports an ongoing malicious campaign targeting Czech organizations that uses a PowerShell LNK-based loader to deploy a previously unreported botnet named PowMix; the malware performs AMSI bypass, in-memory execution, creates scheduled-task persistence, generates unique Bot IDs, and uses randomized, REST-like C2 beaconing (abusing herokuapp.com) with encrypted heartbeats to evade detection. The report includes victimology, detailed technical analysis of the loader and PowMix payload, supported IOCs and signatures, and notes similarities to the earlier ZipLine campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.