216.73.216.6

ZipLine Phishing Campaign Targets U.S. Manufacturing

· Published 27/08/2025 19:13 · Modified 27/08/2025 19:42

Export JSON

Essential information

Published
27/08/2025 19:13
Modified
27/08/2025 19:42
Tags
2025-08-27 dns tunneling manufacturing mixshell phishing zipline
Related entities
32 observables, 4 techniques (mitre), 1 malware, 9 others

Description

A sophisticated campaign called is targeting U.S. companies, especially those in supply chain-critical sectors. The attackers initiate contact through company contact forms, leading to weeks-long email conversations before delivering malicious payloads. They use legitimate-looking business interactions and AI-related pretexts to build trust. The campaign employs a custom malware called , which uses DNS TXT tunneling for command and control. The attackers utilize domains matching registered U.S. companies and maintain similar template websites across multiple domains. The campaign primarily targets U.S.-based organizations in industrial , hardware, semiconductors, and other sectors, affecting both large enterprises and smaller businesses.

External references