
TA505 Fake Purchase Order Hides JS Payload 70 Engines Cannot See
A spear-phishing campaign attributed to TA505 is circulating a Varist-packed RAR archive disguised as a purchase order, concealing a JavaScript payload that evades 70 of 76 antivirus engines. The inner dropper uses timing-based sandbox evasion and heavy Unicode obfuscation to beacon a PureHVNC command-and-control channel hosted on a seven-year-old dormant domain quietly reactivated with a fresh wildcard TLS certificate.
A spear-phishing campaign attributed to TA505 is circulating a Varist-packed RAR archive named after a fake purchase order — but the real detection problem sits one extraction step deeper: the JavaScript payload inside evades 70 of 76 antivirus engines despite both sandboxes that processed it returning unambiguous malicious verdicts, and despite an Abuse.ch IDS rule already flagging its PureHVNC command-and-control certificate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read