FILEMembers
FILE

Vessel-Doc Phishing Campaign Adds Uncharacterised Hashes, Core Tradecraft Unchanged

A packed .NET AgentTesla dropper disguised as a Q88 vessel-particulars document is hitting thirteen countries, filtering out sandbox environments via an ip-api.com geolocation check before harvesting credentials. A follow-up indicator update adds two entirely uncharacterised file hashes, weakening rather than strengthening the evidentiary base, while an APT29/Remcos attribution in the threat metadata conflicts with sandbox-confirmed AgentTesla findings.

May 26, 2026, 11:05 (UTC+9)Last seenJun 10, 2026Severity72ByCTX TeamActorAPT29MinidionisIOC4MITRE47RegionsAUCZDEEGES

A 901-kilobyte ZIP archive named MV_NATHAN_VSL_MAIN_PARTICULARS+Q88_DETAILS.zip is doing quiet work across at least thirteen countries. The file — first seen on VirusTotal on 2026-05-13 and submitted from two independent sources on the same day — carries a single embedded PE32 .NET assembly whose .text section registers entropy of 7.88, near the theoretical maximum, and declares zero imports.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence