#MiradorShell
Malware/Tool
2026-02-06 • APT-C-28(ScarCruft)利用MiradorShell发起网络攻击的安全预警
MiradorShell v2.0 is an AutoIt-based backdoor deployed in a ScarCruft-linked spear-phishing campaign against Web3 startups and DeFi developers. A ZIP archive contained a decoy document and an investment-themed LNK disguised as a PDF. The shortcut launched a multi-stage chain that downloaded AutoIt3 and an encrypted AU3 script from a likely compromised Korean company website. After decryption, MiradorShell established persistence with a misspelled Windows Update scheduled task that executed the backdoor every five minutes.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days