logo

Coronavirus-Themed Document Targets Brazilian Users

ID: 71f8c010-8a9c-5eaf-a999-4942d193b166

STIX ID: report--71f8c010-8a9c-5eaf-a999-4942d193b166

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Technical analysis of a COVID-19 themed macro-based PowerPoint (PPS) observed in the wild that downloads an HTA which, after a timed delay, reverses and decodes a Base64 blob stored in the registry and uses PowerShell to load a .NET njRAT assembly. The report includes file hashes, C2 hostname and port, registry keys, mutex and other IoCs, and describes njRAT behaviors including information collection, keylogging, persistence and communication with the attacker C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.