Detecting Multi-Stage Infection Chains Madness
ID: 72b4f764-4c24-5696-b6cd-70c7b68a7943
STIX ID: report--72b4f764-4c24-5696-b6cd-70c7b68a7943
Feed Name: Sekoia.io Blog
Date Published: 2025-04-22
Date Updated: 2026-04-29
Author: Sekoia TDR and Erwan Chevalier
Sekoia TDR reports on a resilient, multi-stage phishing campaign (since at least Feb 2024) that uses Cloudflare tunnel infrastructure and WebDAV to host and deliver AsyncRAT. The chain involves email attachments (.ms-library), LNK -> HTA -> BAT -> Python stages, reflective DLL loading from a JPEG, persistence via Startup VBS/BAT, and C2 using TryCloudflare and dynamic DNS; the report provides IoCs (domains, hashes) and Sigma detection rules to aid detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
