Multistage low-volume attack using AzureEdge and Shopify CDN
ID: f17acfe3-a6de-5bc6-be2b-e5611725a18f
STIX ID: report--f17acfe3-a6de-5bc6-be2b-e5611725a18f
Feed Name: Zscaler Security Research Blog
This report analyzes a multi-stage web attack (delivered via a compromised WooCommerce plugin) that loads staged JavaScript from attacker-controlled CDN hosts, coerces users to download a ZIP containing an LNK which abuses mshta to fetch VBScript and PowerShell; the PowerShell executes inline C# to run a fileless backdoor named METRICA that performs keylogging, active-window capture, screenshots, and HTTPS C2 communication, with provided IoCs (hashes, URLs, domains) and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
