Operation TaxShadow: Tax Phishing Hides In-Memory Malware
ID: 283d5e50-6118-5ecd-af4e-b89f95fe2880
STIX ID: report--283d5e50-6118-5ecd-af4e-b89f95fe2880
Feed Name: securityonline.info
Threat Score
Operation TaxShadow is a sophisticated, multi-stage phishing campaign masquerading as government tax notices that distributes a ZIP archive containing a loader EXE, a malicious SbieDll.dll that installs API hooks and a Mersenne-Twister VM, and an encrypted SbieDll.bin which is reflectively loaded into memory; the malware uses DLL search-order hijacking, memory-only execution, WebSocket-based C2, proxy tunneling, and process injection (e.g., svchost.exe) to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
