KoiLoader Reloaded: New Variant Uses LNK Abuse, Script Chains, and PowerShell to Deliver Stealer Payload
ID: 07750ae1-adce-5e40-ada9-9efc59f00ab4
STIX ID: report--07750ae1-adce-5e40-ada9-9efc59f00ab4
Feed Name: securityonline.info
eSentire’s TRU observed a phishing campaign that uses a ZIP attachment containing a deceptive .lnk that executes hidden PowerShell to download JScript payloads which establish persistence, disable AMSI, and load KoiLoader; KoiLoader performs environment checks and UAC bypasses, then fetches PowerShell stages that install KoiStealer (an info-stealer that harvests credentials, cookies, and browser/app data) and communicates with a custom X25519-based HTTP C2 for command polling and payload injection. The report includes IOCs (filenames, domains) and an emulation toolkit for C2 simulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
