JavaScript Malspam Campaigns
ID: 72872742-1b1e-50c1-abfe-b25d1b9ff4b7
STIX ID: report--72872742-1b1e-50c1-abfe-b25d1b9ff4b7
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ reports ongoing malspam campaigns delivering heavily obfuscated JavaScript masquerading as invoices/receipts; when users allow script execution (ActiveX), the scripts fetch and execute malware payloads (observed Kasidet and Emotet variants) from hardcoded URLs. The report analyzes the obfuscation and deobfuscation steps, infection chain, and notes widespread distribution (10,000+ instances over two weeks), advising caution with email links and layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
