logo

Trojan Infection Through Facebook

ID: 7d6313c6-543c-5d99-93ae-068798389478

STIX ID: report--7d6313c6-543c-5d99-93ae-068798389478

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report documents a social-engineering campaign that uses Facebook messages to distribute a known Trojan dropper (“surprise.exe”). The attacker-controlled domains (linked to IP 89.187.53.64) host the payload or redirect victims to it; VirusTotal flags the binary as a Trojan dropper and third-party reports list additional domains used in the campaign. Users are advised to verify links before clicking to avoid infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.