logo

Multistage low-volume attack using AzureEdge and Shopify CDN

ID: f17acfe3-a6de-5bc6-be2b-e5611725a18f

STIX ID: report--f17acfe3-a6de-5bc6-be2b-e5611725a18f

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a multi-stage web attack (delivered via a compromised WooCommerce plugin) that loads staged JavaScript from attacker-controlled CDN hosts, coerces users to download a ZIP containing an LNK which abuses mshta to fetch VBScript and PowerShell; the PowerShell executes inline C# to run a fileless backdoor named METRICA that performs keylogging, active-window capture, screenshots, and HTTPS C2 communication, with provided IoCs (hashes, URLs, domains) and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.