
DHL-Lure RAR Delivers MassLogger to Construction Firms Across Four Countries
A 946-kilobyte RAR archive disguised as a DHL airway-bill notification is targeting construction-sector organisations in Germany, India, Malaysia, and Turkey. The archive uses debugger-detection and long-sleep logic to defeat automated sandboxes before unpacking a heavily obfuscated .NET credential-harvester onto live workstations.
A 946-kilobyte RAR archive named DHL_AWB#6078538091.rar has been circulating since mid-May 2026 as the opening move in a credential-harvesting campaign targeting construction-sector organisations across Germany, India, Malaysia, and Turkey. The archive is not simply a container — it is itself the first evasion layer, carrying explicit debugger-detection and long-sleep logic that caused one major automated analysis platform to return a clean verdict at 96% confidence while a second correctly…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read