logo

Cascading Shadows: An Attack Chain Approach to Avoid Detection and Complicate Analysis

ID: 51e65a1d-c8b7-5f6e-8b25-f86ac7090a3c

STIX ID: report--51e65a1d-c8b7-5f6e-8b25-f86ac7090a3c

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-04-16

Date Updated: 2026-04-28

Author: Saqib Khanzada

...
...

In December 2024, analysts uncovered a multi-stage phishing campaign delivering Agent Tesla variants via emailed archives containing a .jse downloader that fetches a Base64 PowerShell payload; subsequent stages used either .NET or AutoIt compiled droppers to decrypt payloads and inject malware into legitimate processes (RegAsm/RegSvcs), with the report detailing AutoIt debugging, shellcode execution, IOCs (hashes, payload URLs, and FTP credentials), and recommended detections and mitigations via Palo Alto Networks products and Unit 42.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.