Campaign · active
Repeated static TTP
Correlated evidence: js_hidden_powershell:hidden / non-interactive powershell invocation in package code — `-windowstyle hidden`, `irm | iex`, `windowshide: true`, or equivalent — used to download-and-run payloads on windows installers.
194 releases186 max score90 confidence
Member releases
Timeline
| Date (UTC) | Event |
|---|---|
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-03 | expanded_campaign |
| 2026-06-02 | expanded_campaign |
| 2026-06-02 | expanded_campaign |
| 2026-06-02 | expanded_campaign |
| 2026-06-02 | expanded_campaign |
| 2026-06-02 | expanded_campaign |
| 2026-06-02 | expanded_campaign |