FILEMembers
FILE

TA505 Dropper Sleeps Past Sandboxes, Stages Rockloader in 24 Countries

A sleep-heavy JavaScript dropper disguised as business invoice PDFs is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries. The script stalls long enough to exhaust automated sandbox analysis windows before retrieving a Windows executable attributed to the rockloader family from an actor-controlled Bangladesh-hosted domain.

Jun 9, 2026, 20:32 (UTC+9)Last seenJun 9, 2026Severity77ByCTX TeamActorTA505Hive0065IOC42RegionsAEATAZBDBO

A roughly one-megabyte JavaScript file — encoded in UTF-16 little-endian, packed by Varist, and bearing filenames that mimic business invoice PDFs — is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries, functioning as the first stage of a delivery chain that culminates in the download of a Windows executable attributed to the rockloader family.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence