In these observed campaigns, a ZIP archive containing an LNK file is downloaded upon clicking the provided URLs. Extracting and running the LNK file ultimately leads to Astaroth’s installation. During installation, Astaroth creates an LNK file in the system’s Startup folder to maintain persistence on the infected system and ensure Astaroth runs upon system startup. While TA2725 has recently been primarily distributing Astaroth, they have also been tracked spreading Mispadu, Grandoreiro, and, most recently, ScreenConnect. |