logo

WebDAV-as-a-Service: Uncovering the infrastructure behind Emmenhtal loader distribution

ID: b733d0af-e64f-5201-8d8c-b442f9fd3cd8

STIX ID: report--b733d0af-e64f-5201-8d8c-b442f9fd3cd8

Feed Name: Sekoia.io Blog

Threat Score
70/100

Date Published: 2024-09-19

Date Updated: 2026-04-29

Author: Marc N. and Sekoia TDR

...
...

Since December 2023 Sekoia TDR tracked a WebDAV-based infrastructure hosting weaponized .lnk files that trigger mshta.exe to fetch the Emmenhtal/PeakLight memory-only loader; this infrastructure has been used to distribute a wide set of malware (many infostealers and commodity loaders), includes extensive IOCs (URLs and IPs), shows repeated ASN hosting patterns, and is likely operated as a criminal Infrastructure-as-a-Service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.