FILEMembers
FILE

Gorgon Group Wraps Commodity Stealers in Four-Layer Evasion Stack

A GZIP archive disguised as a supplier quotation request delivers ponystealer and predator_pain payloads to Windows endpoints. The packaging pipeline — container-level AV suppression, PEiD packing, a fabricated 1992 PE timestamp, and a high-entropy resource section — is engineered to defeat static detection and disrupt forensic triage at each stage.

Jun 25, 2026, 14:18 (UTC+9)Last seenJun 25, 2026Severity72ByCTX TeamActorGorgon GroupSubaatIOC7MITRE41

A GZIP archive bearing the filename "RFQ Number QUO19009852.exe" is the outermost layer of a credential-theft operation that CTX Team has been tracking against Windows endpoints. The file is unremarkable at first glance — a compressed archive mimicking a supplier quotation request, the kind of attachment that moves through purchasing inboxes without triggering much suspicion.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence