PowMix Botnet Targets Czech Companies and Finance Job Seekers With Randomized C2 Communications
Cisco Talos has uncovered a botnet campaign called PowMix that primarily targets human resources departments at Czech companies, as well as job seekers in the finance and IT sectors. The attackers use job-search and salary-related themes to increase the likelihood that recipients will open malicious files. Once a computer is compromised, they may steal corporate data and establish persistent access, posing a cybersecurity threat to recruitment processes and the financial sector.
The attackers have recently conducted phishing attacks using ZIP archives disguised as salary data to install the PowMix malware. The malware can bypass Windows’ Antimalware Scan Interface, or AMSI, and randomly select command-and-control servers, reducing the likelihood that fixed network indicators will be blocked. Cisco Talos has not disclosed the number of victims, financial losses or the exact date the attacks began.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.