APTMembers
APT

DHL-Lure RAR Delivers MassLogger to Construction Firms Across Four Countries

A 946-kilobyte RAR archive disguised as a DHL airway-bill notification is targeting construction-sector organisations in Germany, India, Malaysia, and Turkey. The archive uses debugger-detection and long-sleep logic to defeat automated sandboxes before unpacking a heavily obfuscated .NET credential-harvester onto live workstations.

Jun 17, 2026, 23:57 (UTC+9)Last seenJun 17, 2026Severity72ByCTX TeamActorAPT29MinidionisIOC3MITRE23RegionsDEINMYTR

A 946-kilobyte RAR archive named DHL_AWB#6078538091.rar has been circulating since mid-May 2026 as the opening move in a credential-harvesting campaign targeting construction-sector organisations across Germany, India, Malaysia, and Turkey. The archive is not simply a container — it is itself the first evasion layer, carrying explicit debugger-detection and long-sleep logic that caused one major automated analysis platform to return a clean verdict at 96% confidence while a second correctly…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence