logo

Gone Phishing: An Analysis of a Targeted User Attack

ID: 2aeb2dcc-3e46-535e-9b4f-8eef47ad738d

STIX ID: report--2aeb2dcc-3e46-535e-9b4f-8eef47ad738d

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress investigators detail a phishing incident in which a user-received ZIP containing a decoy PDF and a malicious Windows shortcut launched mshta and PowerShell to download and execute a Go-based loader that unpacked and ran an XWorm RAT; the malware established persistence via a scheduled task and used obfuscation and BITS/Transfer.sh downloads to evade detection, illustrating the need to combine security awareness with EDR/MDR defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.