
TA505 Dropper Sleeps Past Sandboxes, Stages Rockloader in 24 Countries
A sleep-heavy JavaScript dropper disguised as business invoice PDFs is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries. The script stalls long enough to exhaust automated sandbox analysis windows before retrieving a Windows executable attributed to the rockloader family from an actor-controlled Bangladesh-hosted domain.
A roughly one-megabyte JavaScript file — encoded in UTF-16 little-endian, packed by Varist, and bearing filenames that mimic business invoice PDFs — is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries, functioning as the first stage of a delivery chain that culminates in the download of a Windows executable attributed to the rockloader family.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read