logo

JavaScript Malspam Campaigns

ID: 72872742-1b1e-50c1-abfe-b25d1b9ff4b7

STIX ID: report--72872742-1b1e-50c1-abfe-b25d1b9ff4b7

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ reports ongoing malspam campaigns delivering heavily obfuscated JavaScript masquerading as invoices/receipts; when users allow script execution (ActiveX), the scripts fetch and execute malware payloads (observed Kasidet and Emotet variants) from hardcoded URLs. The report analyzes the obfuscation and deobfuscation steps, infection chain, and notes widespread distribution (10,000+ instances over two weeks), advising caution with email links and layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.