Campaign · stale
Repeated static TTP
Correlated evidence: js_hidden_powershell:hidden / non-interactive powershell invocation in package code — typically `-windowstyle hidden`, `irm | iex`, or `windowshide: true` — used to download-and-run payloads on windows installers.
10 releases102 max score90 confidence
Member releases
Timeline
| Date (UTC) | Event |
|---|---|
| 2026-05-27 | stale_campaign |
| 2026-05-27 | score_increased |
| 2026-05-27 | expanded_campaign |
| 2026-05-27 | score_increased |
| 2026-05-27 | expanded_campaign |
| 2026-05-27 | expanded_campaign |
| 2026-05-27 | expanded_campaign |
| 2026-05-27 | expanded_campaign |
| 2026-05-27 | expanded_campaign |
| 2026-05-27 | new_campaign |