FILEMembers
FILE

'Shipping Advice' Phishing Chain Skips Fingerprints, Leans on Disposable Hosting

A RAR-wrapped JavaScript dropper disguised as shipping paperwork stages a font-masquerading payload and checks its victim's IP before touching a single, disposable Namecheap-hosted domain. Tied loosely to TA505/RockLoader, the campaign shows almost no shared imphash or code-signing evidence — its strength is behavioural, not structural.

Jul 19, 2026, 13:46 (UTC+9)Last seenJul 19, 2026Severity100ByCTX TeamActorTA505Hive0065IOC6RegionsBDCACHDEDK

A phishing wave dressed up as a "shipping advice" notice is running a tight, four-step reconnaissance-and-drop chain before it ever touches a durable piece of infrastructure. The sequence — a RAR-wrapped JavaScript dropper that stages a font-disguised payload and then queries the victim's own external IP address before reaching out to a single, disposable web host — reads less like a bespoke intrusion tool and more like a lean, repeatable delivery kit.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence