logo

Steal-It Campaign

ID: b6317b43-8daa-548a-ab29-a31d4f87a8d7

STIX ID: report--b6317b43-8daa-548a-ab29-a31d4f87a8d7

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report documents an infection chain that lures Belgian users with a spoofed "Windows Update" theme: a malicious LNK delivered in a ZIP opens geofenced JavaScript which drops batch/PowerShell stages, maintains persistence via the Startup folder and CertUtil, and exfiltrates command output and file paths (tasklist, systeminfo, Get-ChildItem) to remote endpoints (mockbin.org/run.mocky.io), with similarities to activity attributed to APT28.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.