FILEMembers
FILE

A ZIP, a Batch Script, a Fake PDF Previewer: Inside a Staged Malware Chain

A cluster of 24 file indicators submitted in June 2026 reveals a staged commodity-malware delivery chain: a ZIP archive dropping a single batch script, an MSIL loader disguised as a 'PDF Previewer' utility, and a separate multi-capability stealer sample. No named actor or hosting infrastructure anchors the set — the signal is entirely in the tradecraft.

Jun 26, 2026, 10:15 (UTC+9)Last seenJul 2, 2026Severity98ByCTX TeamIOC26MITRE38RegionsBREGESGBGR

A cluster of 24 file indicators submitted between June 1 and June 24, 2026 traces a delivery pattern that looks less like a single tailored intrusion and more like an assembly line: an archive carrying one batch script, a MSIL loader wearing the metadata of a document-preview utility, and a separate stealer sample whose YARA hits span everything from ransomware command detection to crypto-wallet browser extension harvesting.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence