
Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign
A trojanised Microsoft Activation Scripts ZIP is funnelling compromised hosts toward a three-node, multi-autonomous-system C2 architecture with no shared certificate or DNS fingerprint between nodes. The campaign pairs commodity software-piracy lures and a recycled 2019 batch script with operationally sophisticated infrastructure — including a Thai national-telecom IP presenting a mismatched wildcard certificate — targeting the telecommunications sector for espionage and disruption.
A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read