Military-themed Email Scam Spreads Malware to Infect Pakistani Users
ID: 6a677051-22e2-5756-b8af-45dfc6aed21f
STIX ID: report--6a677051-22e2-5756-b8af-45dfc6aed21f
Feed Name: The Hacker News
Researchers disclosed a phishing campaign dubbed PHANTOM#SPIKE targeting users in Pakistan by distributing password-protected ZIPs containing a CHM file and a hidden executable (RuntimeIndexer.exe). Opening the CHM displays military-related meeting minutes while silently launching the bundled backdoor, which connects to a remote TCP C2, executes commands via cmd.exe, collects system information and command output (e.g., systeminfo, tasklist, curl to ip-api.com), and establishes persistence through schtasks to maintain covert remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
