logo

Demystifying the full attack chain of MineBridge RAT

ID: b5cb9497-6587-5eef-97b8-b03985a5371a

STIX ID: report--b5cb9497-6587-5eef-97b8-b03985a5371a

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz documents a sophisticated multi-stage campaign (March–May 2021) distributing the MineBridge RAT through fake TradingView Windows installers signed by YUNIVELL, LLC. The attack chain uses staged PowerShell scripts, scheduled tasks named to masquerade as cloud services, reverse SSH tunnels to 86.106.181.183:32672, and DLL side-loading of TeamViewer to enable remote access and data exfiltration; the report includes MITRE ATT&CK mappings and IOCs (file hashes, domains, signer thumbprint, and persistence artifacts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.