HomeSecurityMixShell malware is distributed via Contact Forms

MixShell malware is distributed via Contact Forms

Cybersecurity researchers are highlighting a sophisticated social engineering campaign targeting supply chain-critical manufacturing companies with an in-memory malware known as MixShell . This activity has been codenamed ZipLine by Check Point Research.

MixShell malware

Instead of sending unsolicited phishing emails, attackers initiate contact through a company's public 'Contact Us' form, tricking employees into starting a conversation. Professional, seemingly trustworthy conversations follow, often accompanied by fake NDAs, and then a weaponized ZIP file containing the MixShell malware is delivered.

The attacks have targeted multiple organizations across a variety of sectors and geographic locations, with a focus on entities based in the U.S. Primary targets include companies in the manufacturing industry: companies involved in machinery, metalworking, component manufacturing, and engineered systems. Companies related to hardware and semiconductors, consumer goods, biotechnology, and pharmaceuticals are also affected. Other countries targeted by the ZipLine campaign include Singapore, Japan, and Switzerland.

See also: Phishing Attack Uses UpCrypter to Deliver RAT

The origins and motivations of the campaign remain unclear, but Check Point identified commonalities with attacks previously linked to the UNK_GreenSec threat group .

The ZipLine malware is an example of how threat actors are increasingly leveraging legitimate business workflows, such as communicating with targets through a company’s website, to exploit trust and bypass potential concerns. Unlike previous methods that relied on scare tactics, ZipLine’s approach eschews urgent language, instead engaging victims in multi-day conversations and sometimes instructing them to sign non-disclosure agreements (NDAs) before sending the compromised ZIP files.

MixShell malware is distributed via Contact Forms

MixShell malware: Attack chain

The attack chain includes multi-stage payloads, in-memory execution, and DNS-based command-and-control (C2) channels, allowing the threat actor to remain invisible. The ZIP files contain a Windows shortcut (LNK) that triggers a PowerShell loader, leading to the custom MixShell implant in memory, which uses DNS tunneling and HTTP as alternative C2 mechanisms for remote command execution, file operations, reverse proxying, persistence, and deeper network penetration.

See also: Chinese APT group uses Proxy and VPN services

MixShell also features a PowerShell variant that includes advanced detection and sandbox evasion techniques, uses scheduled tasks for persistence, and provides reverse proxy shell and file download capabilities. The malicious ZIP files are hosted on a sub-domain of herokuapp.com, a legitimate Platform-as-a-Service (PaaS) platform that provides infrastructure for hosting web applications – further demonstrating the threat actor’s exploitation of legitimate services to integrate with normal enterprise network activity.

The LNK file responsible for starting the execution chain also displays a decoy document included in the ZIP file to avoid potential suspicion. However, Check Point noted that not all ZIP files associated with the Heroku domain are malicious. This suggests customized real-time malware delivery based on certain criteria.

“In many cases, the attacker uses domains that match the names of LLCs registered in the US and, in some cases, may have previously belonged to legitimate businesses,” Check Point said. “The attacker maintains similar template websites for all of these companies, suggesting a well-planned and optimized campaign on a large scale.”

See also: Chinese hackers UNC6384 target diplomats with new techniques

MixShell malware is distributed via Contact Forms

The campaign poses serious risks for companies, as it can lead to intellectual property theft and ransomware attacks , business email compromise , and account theft .

“The ZipLine campaign is a wake-up call for any business that believes phishing is simply about suspicious links in emails,” said Sergey Shykevich, threat intelligence group director at Check Point Research.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

«Attackers are innovating – combining human psychology, trusted communication channels and timely AI bait. To stay secure, organizations must adopt prevention-oriented defenses, guided by AI, and build a culture of vigilance that treats every incoming interaction as a potential threat».

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS