logo

Dissecting A Multi-Stage PowerShell Campaign Using Chisel

ID: 254031a2-7f47-51ba-a764-0db2b5c0782b

STIX ID: report--254031a2-7f47-51ba-a764-0db2b5c0782b

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-07-16

...
...

CRIL identified a sophisticated multi-stage infection chain that starts with a malicious LNK invoking an obfuscated PowerShell payload which drops secondary and tertiary PowerShell stages to maintain persistence, communicate with C2 (https://c2.innov-eula.com and https://ligolo.innov-eula.com), and execute received commands; an open directory hosts the LNK and a Chisel DLL used to create tunnels (via a Netskope proxy) for covert C2 and lateral movement, and the report supplies IOCs (SHA256 hashes, domains, URLs) and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.