216.73.216.6

A security alert regarding APT-C-28 (ScarCruft) using MiradorShell to launch a cyberattack.

· Published 09/02/2026 10:18 · Modified 09/02/2026 11:44

Export JSON

Essential information

Published
09/02/2026 10:18
Modified
09/02/2026 11:44
Tags
2026-02-09 backdoor miradorshell phishing scarcruft
Related entities
4 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 2 others

Description

A recent investigation reveals that the APT-C-28 () group has expanded its targets to include the cryptocurrency industry. The group employs sophisticated tactics, using LNK files disguised as PDFs to lure victims with investment proposals ranging from $1-3 million. Upon execution, a multi-stage payload deployment occurs, ultimately installing v2.0 to gain system control. The attack chain involves file downloads, decryption, and the creation of scheduled tasks for persistence. , an AutoIt-based , connects to a command and control server, offering reverse shell capabilities, file management, remote program execution, and victim fingerprinting. The malware employs various evasion techniques, including inline library files and direct API calls.

External references