FILEMembers
FILE

Fake Invoice Lure Ships Same Downloader in PowerShell and JavaScript

A purchase-order-themed RAR archive impersonating a signed PDF invoice drops an identical sleestak_payload_1.bin downloader in both .ps1 and .js form, hedging against a single script engine being blocked. The kit, linked to TA505/Hive0065 rockloader tradecraft, stages further delivery through a South African VPS whose certificate also fronts a second, unrelated lure domain.

Aug 24, 2026, 06:37 (UTC+9)Last seenAug 24, 2026Severity77ByCTX TeamActorTA505Hive0065IOC11RegionsDEINITTHUS

A purchase-order-themed archive built to impersonate a signed PDF invoice — PO_400269712_Signed_Copy.pdf.txz — has turned up alongside a matching downloader kit that ships the same payload twice: once as a PowerShell script and once as JavaScript, both carrying the identical internal name sleestak_payload_1.bin, both exactly 64KB, and both first observed on the same day, 2026-08-12, with zero antivirus detections on either.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence