logo

Phishing Page Uses File Converter To Spread RedLine Stealer

ID: 0314238c-32b1-567d-8a40-6e6b165cfe78

STIX ID: report--0314238c-32b1-567d-8a40-6e6b165cfe78

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-27

Date Updated: 2026-07-16

...
...

## Executive summary A phishing site impersonating the Convertio online file-conversion service distributes a ZIP containing a malicious .lnk that fetches BAT scripts and an EXE; the scripts add Windows Defender exclusions via PowerShell and execute a payload identified as RedLine Stealer, which harvests credentials, browser data, cryptocurrency wallets, and system information. The report includes technical indicators (file hashes, distribution URLs), a process tree, MITRE ATT&CK mappings, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.