logo

Don’t trust ‘secure mail’! malicious Files Impersonating Credit Card Companies Are Being Distributed

ID: f450ef62-a8b7-5af4-8bab-52b46e74e862

STIX ID: report--f450ef62-a8b7-5af4-8bab-52b46e74e862

Feed Name: ASEC

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-27

Author: ATCP

...
...

**Executive summary:** AhnLab observed a phishing campaign impersonating a Korean credit card company that delivers LNK files which invoke mshta to run obfuscated VBScript and fetch decoy documents and multi-stage malware; the payload adapts its execution based on whether Windows Defender is running, downloading and decrypting different components (pipe.zip => 1.log/1.ps1/2.log for backdoor/infosteal/keylogging, or user.txt/sys.log => sys.dll and additional droppers) to perform credential and cookie theft, keylogging, clipboard theft, remote command execution, and downloader activity; recommended mitigations include checking registries and deleting suspicious files in %TEMP% and %LOCALAPPDATA%.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.