Gone Phishing: An Analysis of a Targeted User Attack
ID: 2aeb2dcc-3e46-535e-9b4f-8eef47ad738d
STIX ID: report--2aeb2dcc-3e46-535e-9b4f-8eef47ad738d
Feed Name: Huntress Blog
Threat Score
Huntress investigators detail a phishing incident in which a user-received ZIP containing a decoy PDF and a malicious Windows shortcut launched mshta and PowerShell to download and execute a Go-based loader that unpacked and ran an XWorm RAT; the malware established persistence via a scheduled task and used obfuscation and BITS/Transfer.sh downloads to evade detection, illustrating the need to combine security awareness with EDR/MDR defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
