Cybersecurity researchers are highlighting a sophisticated social engineering campaign targeting supply chain-critical manufacturing companies with an in-memory malware known as MixShell . This activity has been codenamed ZipLine by Check Point Research.

Instead of sending unsolicited phishing emails, attackers initiate contact through a company's public 'Contact Us' form, tricking employees into starting a conversation. Professional, seemingly trustworthy conversations follow, often accompanied by fake NDAs, and then a weaponized ZIP file containing the MixShell malware is delivered.
The attacks have targeted multiple organizations across a variety of sectors and geographic locations, with a focus on entities based in the U.S. Primary targets include companies in the manufacturing industry: companies involved in machinery, metalworking, component manufacturing, and engineered systems. Companies related to hardware and semiconductors, consumer goods, biotechnology, and pharmaceuticals are also affected. Other countries targeted by the ZipLine campaign include Singapore, Japan, and Switzerland.
See also: Phishing Attack Uses UpCrypter to Deliver RAT
The origins and motivations of the campaign remain unclear, but Check Point identified commonalities with attacks previously linked to the UNK_GreenSec threat group .
The ZipLine malware is an example of how threat actors are increasingly leveraging legitimate business workflows, such as communicating with targets through a company’s website, to exploit trust and bypass potential concerns. Unlike previous methods that relied on scare tactics, ZipLine’s approach eschews urgent language, instead engaging victims in multi-day conversations and sometimes instructing them to sign non-disclosure agreements (NDAs) before sending the compromised ZIP files.

MixShell malware: Attack chain
The attack chain includes multi-stage payloads, in-memory execution, and DNS-based command-and-control (C2) channels, allowing the threat actor to remain invisible. The ZIP files contain a Windows shortcut (LNK) that triggers a PowerShell loader, leading to the custom MixShell implant in memory, which uses DNS tunneling and HTTP as alternative C2 mechanisms for remote command execution, file operations, reverse proxying, persistence, and deeper network penetration.
See also: Chinese APT group uses Proxy and VPN services
MixShell also features a PowerShell variant that includes advanced detection and sandbox evasion techniques, uses scheduled tasks for persistence, and provides reverse proxy shell and file download capabilities. The malicious ZIP files are hosted on a sub-domain of herokuapp.com, a legitimate Platform-as-a-Service (PaaS) platform that provides infrastructure for hosting web applications – further demonstrating the threat actor’s exploitation of legitimate services to integrate with normal enterprise network activity.
The LNK file responsible for starting the execution chain also displays a decoy document included in the ZIP file to avoid potential suspicion. However, Check Point noted that not all ZIP files associated with the Heroku domain are malicious. This suggests customized real-time malware delivery based on certain criteria.
“In many cases, the attacker uses domains that match the names of LLCs registered in the US and, in some cases, may have previously belonged to legitimate businesses,” Check Point said. “The attacker maintains similar template websites for all of these companies, suggesting a well-planned and optimized campaign on a large scale.”
See also: Chinese hackers UNC6384 target diplomats with new techniques

The campaign poses serious risks for companies, as it can lead to intellectual property theft and ransomware attacks , business email compromise , and account theft .
“The ZipLine campaign is a wake-up call for any business that believes phishing is simply about suspicious links in emails,” said Sergey Shykevich, threat intelligence group director at Check Point Research.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
«Attackers are innovating – combining human psychology, trusted communication channels and timely AI bait. To stay secure, organizations must adopt prevention-oriented defenses, guided by AI, and build a culture of vigilance that treats every incoming interaction as a potential threat».
