Phishing Page Uses File Converter To Spread RedLine Stealer
ID: 0314238c-32b1-567d-8a40-6e6b165cfe78
STIX ID: report--0314238c-32b1-567d-8a40-6e6b165cfe78
Feed Name: Cyble Blog
## Executive summary A phishing site impersonating the Convertio online file-conversion service distributes a ZIP containing a malicious .lnk that fetches BAT scripts and an EXE; the scripts add Windows Defender exclusions via PowerShell and execute a payload identified as RedLine Stealer, which harvests credentials, browser data, cryptocurrency wallets, and system information. The report includes technical indicators (file hashes, distribution URLs), a process tree, MITRE ATT&CK mappings, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
