logo

Help Center URL Validation Vulnerability Campaign

ID: 4b530faa-18dc-5f69-919d-92ecdf93005f

STIX ID: report--4b530faa-18dc-5f69-919d-92ecdf93005f

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report documents an active web-exploit campaign using dyndns-hosted domains and compromised websites to deliver Windows executables and Java .jar payloads. The dropper uses Windows Script Host (cscript) to assemble a .js downloader that fetches an executable (bonjour.exe) and kills processes matching "help", while associated network indicators and ThreatExpert callbacks point to additional infrastructure and piecemeal payload delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.