logo

'ZipLine' Phishers Flip Script as Victims Email First

ID: a2bb1be9-21ca-530c-a086-1d5b926921c1

STIX ID: report--a2bb1be9-21ca-530c-a086-1d5b926921c1

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-08-27

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

**Executive summary:** The ZipLine campaign is a financially motivated phishing operation that engineers targets to initiate contact via corporate 'Contact Us' forms, builds credibility over weeks, and ultimately delivers weaponized ZIP archives containing a malicious LNK which launches an in-memory PowerShell implant (MixShell) that provides persistence and command-and-control; attackers leverage abandoned/dormant legitimate domains and Heroku hosting to evade detection and target industrial, hardware, semiconductor, biotech, and other supply-chain-critical organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.