
Fake Invoice Lure Ships Same Downloader in PowerShell and JavaScript
A purchase-order-themed RAR archive impersonating a signed PDF invoice drops an identical sleestak_payload_1.bin downloader in both .ps1 and .js form, hedging against a single script engine being blocked. The kit, linked to TA505/Hive0065 rockloader tradecraft, stages further delivery through a South African VPS whose certificate also fronts a second, unrelated lure domain.
A purchase-order-themed archive built to impersonate a signed PDF invoice — PO_400269712_Signed_Copy.pdf.txz — has turned up alongside a matching downloader kit that ships the same payload twice: once as a PowerShell script and once as JavaScript, both carrying the identical internal name sleestak_payload_1.bin, both exactly 64KB, and both first observed on the same day, 2026-08-12, with zero antivirus detections on either.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read