Trade with caution - bad guys are stealing
ID: 62fcc458-e3d9-521b-8f19-60597394d15f
STIX ID: report--62fcc458-e3d9-521b-8f19-60597394d15f
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz investigated an active campaign where threat actors hosted a look‑alike TradingView site and a digitally-signed malicious Windows installer (TradingVlev_x32_x64bit.exe) that installs a SmokeLoader DLL and subsequently downloads ArkeiStealer payloads. The report provides the end-to-end attack chain (SEO poisoning -> fake site -> signed installer -> SmokeLoader C2 -> ArkeiStealer fetches), MITRE ATT&CK mappings, and detailed IoCs (file hashes, domains, and C2 IPs) to aid detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
