#MiradorShell

Malware/Tool

2026-02-06 • APT-C-28(ScarCruft)利用MiradorShell发起网络攻击的安全预警

MiradorShell v2.0 is an AutoIt-based backdoor deployed in a ScarCruft-linked spear-phishing campaign against Web3 startups and DeFi developers. A ZIP archive contained a decoy document and an investment-themed LNK disguised as a PDF. The shortcut launched a multi-stage chain that downloaded AutoIt3 and an encrypted AU3 script from a likely compromised Korean company website. After decryption, MiradorShell established persistence with a misspelled Windows Update scheduled task that executed the backdoor every five minutes.

Tagged Reports

« Back