FILEMembers
FILE

LHA Lure Drops PureLog Stealer and XWorm With 0/76 Persistence Layer

A purchase-order phishing campaign is circulating a ZIP/LHA double-extension archive across engineering, retail, and telecom firms in five countries. The .NET Reactor-obfuscated payload bundles PureLog Stealer and XWorm, while two persistence components — a VBS startup stub and a SetupComplete.cmd hook — each achieve zero antivirus detections. A TLS certificate CN mismatch to 'relaysession.com' on the DDNS command-and-control node provides the clearest pivot for hunting additional operator infrastructure.

Jun 20, 2026, 16:33 (UTC+9)Last seenJun 21, 2026Severity100ByCTX TeamIOC29MITRE60RegionsBACOCZMYUS

A 935-kilobyte ZIP archive named docPO-Q-2606010-ASN _ ZBSPR26-007.PDF(849KB).LHA is circulating as a spearphishing attachment across engineering firms, retail organisations, and telecommunications providers in Bosnia-Herzegovina, Colombia, the Czech Republic, Malaysia, and the United States. The filename is a layered deception: the .LHA extension appended after a fake PDF size annotation is engineered to make the archive read as a harmless purchase-order document to a distracted procurement or…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence