logo

TOITOIN Trojan: A New Multi-Stage Attack Targeting LATAM

ID: 31dd48cf-0f23-536a-9834-ac3a3b2d81a2

STIX ID: report--31dd48cf-0f23-536a-9834-ac3a3b2d81a2

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report provides a detailed technical analysis of the multi-stage TOITOIN infection chain: a downloader that creates persistence via LNK and scheduled restart, sideloading of a malicious Krita Loader DLL (ffmpeg.dll) into a signed ZOHO binary, chained loader/injector DLLs that decode embedded payloads from JPG files, a UAC bypass leveraging COM Elevation Moniker to gain elevated execution, and a final TOITOIN backdoor that decodes an INI configuration, discovers installed browsers and system attributes, and contacts multiple C2 URLs; the report contains IOCs (C2 URLs, PDB paths, filenames, mutex names) and decryption logic to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.