logo

Trade with caution - bad guys are stealing

ID: 62fcc458-e3d9-521b-8f19-60597394d15f

STIX ID: report--62fcc458-e3d9-521b-8f19-60597394d15f

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz investigated an active campaign where threat actors hosted a look‑alike TradingView site and a digitally-signed malicious Windows installer (TradingVlev_x32_x64bit.exe) that installs a SmokeLoader DLL and subsequently downloads ArkeiStealer payloads. The report provides the end-to-end attack chain (SEO poisoning -> fake site -> signed installer -> SmokeLoader C2 -> ArkeiStealer fetches), MITRE ATT&CK mappings, and detailed IoCs (file hashes, domains, and C2 IPs) to aid detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.