logo

APT-31 Leverages COVID-19 Vaccine Theme

ID: fc79e582-7320-5a99-89f9-68f11f996adb

STIX ID: report--fc79e582-7320-5a99-89f9-68f11f996adb

Feed Name: Zscaler Security Research Blog

Threat Score
88/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzes an APT-31 campaign that distributed malicious MSI installers (masquerading as COVID-19 vaccine PDFs) hosted on attacker GitHub accounts; the MSI drops a PyInstaller-packed Python binary that uses Dropbox API for C2, steals browser credentials, establishes persistence via a Run registry key, and exfiltrates data. The report includes attack flow reconstruction, decompiled Python payload, MITRE ATT&CK mapping, and extensive IOCs (MD5 hashes, filenames, GitHub URLs, LNK metadata).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.