WebDAV-as-a-Service: Uncovering the infrastructure behind Emmenhtal loader distribution
ID: b733d0af-e64f-5201-8d8c-b442f9fd3cd8
STIX ID: report--b733d0af-e64f-5201-8d8c-b442f9fd3cd8
Feed Name: Sekoia.io Blog
Threat Score
Since December 2023 Sekoia TDR tracked a WebDAV-based infrastructure hosting weaponized .lnk files that trigger mshta.exe to fetch the Emmenhtal/PeakLight memory-only loader; this infrastructure has been used to distribute a wide set of malware (many infostealers and commodity loaders), includes extensive IOCs (URLs and IPs), shows repeated ASN hosting patterns, and is likely operated as a criminal Infrastructure-as-a-Service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
