Don’t Click That Shortcut: Phorpiex Botnet Hides in “Your Document” Emails
ID: 9548a67e-209d-5d4e-a367-7e4a42d837fe
STIX ID: report--9548a67e-209d-5d4e-a367-7e4a42d837fe
Feed Name: securityonline.info
Threat Score
A high-volume phishing campaign is using ZIP attachments containing malicious .LNK shortcuts disguised as documents (via double extensions and stolen icons) to execute PowerShell commands that fetch and launch a second-stage payload — Phorpiex/Trik — allowing ransomware/cryptominer distribution; defenders are advised to block .LNK files at email gateways and enable visible file extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
