logo

Military-themed Email Scam Spreads Malware to Infect Pakistani Users

ID: 6a677051-22e2-5756-b8af-45dfc6aed21f

STIX ID: report--6a677051-22e2-5756-b8af-45dfc6aed21f

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-06-21

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a phishing campaign dubbed PHANTOM#SPIKE targeting users in Pakistan by distributing password-protected ZIPs containing a CHM file and a hidden executable (RuntimeIndexer.exe). Opening the CHM displays military-related meeting minutes while silently launching the bundled backdoor, which connects to a remote TCP C2, executes commands via cmd.exe, collects system information and command output (e.g., systeminfo, tasklist, curl to ip-api.com), and establishes persistence through schtasks to maintain covert remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.