New “PowMix” Botnet Preys on Czech Workforce with Lure of Compliance
ID: 37af8f7f-aa73-5eb1-a6f5-80d0a1797305
STIX ID: report--37af8f7f-aa73-5eb1-a6f5-80d0a1797305
Feed Name: securityonline.info
Cisco Talos researchers describe a sophisticated, stealthy botnet named “PowMix” targeting HR, legal, and recruitment teams in the Czech Republic since December 2025. Attackers use ZIP archives containing Windows shortcuts that launch PowerShell loaders, perform an AMSI reflection-based bypass to run in memory, and employ randomized beaconing and Heroku-hosted C2 infrastructure to blend with legitimate REST traffic. The botnet supports remote commands for self-deletion and C2 migration, shows tactical overlap with the earlier ZipLine/MixShell campaigns, and appears focused on espionage and long-term access rather than overt destructive activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
