logo

Don’t Click That Shortcut: Phorpiex Botnet Hides in “Your Document” Emails

ID: 9548a67e-209d-5d4e-a367-7e4a42d837fe

STIX ID: report--9548a67e-209d-5d4e-a367-7e4a42d837fe

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-volume phishing campaign is using ZIP attachments containing malicious .LNK shortcuts disguised as documents (via double extensions and stolen icons) to execute PowerShell commands that fetch and launch a second-stage payload — Phorpiex/Trik — allowing ransomware/cryptominer distribution; defenders are advised to block .LNK files at email gateways and enable visible file extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.