Mark RadarMARK RADAR
EN

PowMix Botnet Targets Czech Companies and Finance Job Seekers With Randomized C2 Communications

1 reports · First detected 2026-04-20 · Last active 2026-04-20

Cisco Talos has uncovered a botnet campaign called PowMix that primarily targets human resources departments at Czech companies, as well as job seekers in the finance and IT sectors. The attackers use job-search and salary-related themes to increase the likelihood that recipients will open malicious files. Once a computer is compromised, they may steal corporate data and establish persistent access, posing a cybersecurity threat to recruitment processes and the financial sector.

The attackers have recently conducted phishing attacks using ZIP archives disguised as salary data to install the PowMix malware. The malware can bypass Windows’ Antimalware Scan Interface, or AMSI, and randomly select command-and-control servers, reducing the likelihood that fixed network indicators will be blocked. Cisco Talos has not disclosed the number of victims, financial losses or the exact date the attacks began.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR