C&CMembers
C&C

Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign

A trojanised Microsoft Activation Scripts ZIP is funnelling compromised hosts toward a three-node, multi-autonomous-system C2 architecture with no shared certificate or DNS fingerprint between nodes. The campaign pairs commodity software-piracy lures and a recycled 2019 batch script with operationally sophisticated infrastructure — including a Thai national-telecom IP presenting a mismatched wildcard certificate — targeting the telecommunications sector for espionage and disruption.

May 27, 2026, 21:54 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamActorTA505Hive0065IOC22MITRE4

A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence