
Gorgon Group Wraps Commodity Stealers in Four-Layer Evasion Stack
A GZIP archive disguised as a supplier quotation request delivers ponystealer and predator_pain payloads to Windows endpoints. The packaging pipeline — container-level AV suppression, PEiD packing, a fabricated 1992 PE timestamp, and a high-entropy resource section — is engineered to defeat static detection and disrupt forensic triage at each stage.
A GZIP archive bearing the filename "RFQ Number QUO19009852.exe" is the outermost layer of a credential-theft operation that CTX Team has been tracking against Windows endpoints. The file is unremarkable at first glance — a compressed archive mimicking a supplier quotation request, the kind of attachment that moves through purchasing inboxes without triggering much suspicion.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read