
LHA Lure Drops PureLog Stealer and XWorm With 0/76 Persistence Layer
A purchase-order phishing campaign is circulating a ZIP/LHA double-extension archive across engineering, retail, and telecom firms in five countries. The .NET Reactor-obfuscated payload bundles PureLog Stealer and XWorm, while two persistence components — a VBS startup stub and a SetupComplete.cmd hook — each achieve zero antivirus detections. A TLS certificate CN mismatch to 'relaysession.com' on the DDNS command-and-control node provides the clearest pivot for hunting additional operator infrastructure.
A 935-kilobyte ZIP archive named docPO-Q-2606010-ASN _ ZBSPR26-007.PDF(849KB).LHA is circulating as a spearphishing attachment across engineering firms, retail organisations, and telecommunications providers in Bosnia-Herzegovina, Colombia, the Czech Republic, Malaysia, and the United States. The filename is a layered deception: the .LHA extension appended after a fake PDF size annotation is engineered to make the archive read as a harmless purchase-order document to a distracted procurement or…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read