logo

Unmasking the Infrastructure of a Spearphishing Campaign

ID: 3a334981-f6f3-5453-ab1b-2db53952c55f

STIX ID: report--3a334981-f6f3-5453-ab1b-2db53952c55f

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2025-06-10

Date Updated: 2026-04-27

Author: Ivonne Francia; Mark Ellzey; Senior Security Researcher

...
...

A cluster of 16 open directories hosting heavily obfuscated Visual Basic Script droppers (notably files named "sostener.vbs") were analyzed and found to implement a three-stage installer: VBS -> dynamically generated PowerShell stager -> memory injector -> in-memory RAT execution. Observed payloads include Remcos (multiple strains), LimeRAT, DCRat, and AsyncRAT, with C2 infrastructure using duckdns.org dynamic domains, TLS certificate pivoting, and payload hosting on paste.ee, Bitbucket, and archive.org; the report lists extensive IOCs and suggests a possible but unconfirmed link to APT-C-36.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.