MixShell Malware Targets U.S. Manufacturers in ZipLine Attack

Supply Chain Manufacturers Targeted by ZipLine Campaign Using MixShell Malware and AI-Themed Social Engineering

  • Attackers are targeting supply chain-related manufacturing companies using an in-memory Malware called MixShell.
  • The campaign, identified as ZipLine, uses professional conversations through company contact forms instead of typical phishing emails.
  • Targets include industrial manufacturing, hardware, biotechnology, and other critical sectors in the U.S., Singapore, Japan, and Switzerland.
  • The attack uses multi-stage payloads and blends in with usual business operations by leveraging trusted communication channels and Artificial Intelligence (AI) themes.
  • Experts warn that the campaign can lead to theft, Ransomware, financial fraud, and major supply chain disruptions.

Cybersecurity researchers have reported a new campaign called ZipLine targeting key supply chain manufacturing companies with the MixShell malware. The campaign, mainly affecting U.S. entities as well as organizations in Singapore, Japan, and Switzerland, relies on social engineering and avoids common phishing methods by initiating contact through public “Contact Us” forms on company websites.

- Advertisement -

According to Check Point Research, attackers establish multi-week conversations that appear credible and may include fake non-disclosure agreements (NDAs). After building trust, they deliver a ZIP file containing MixShell, a stealthy malware that operates in the memory of infected computers and is not stored on disk, which helps avoid detection.

The targeted companies operate in sectors such as machinery, metalwork, hardware, semiconductors, consumer goods, biotechnology, and pharmaceuticals. Check Point has found connections between digital certificates used in this campaign and infrastructure previously linked to TransferLoader attacks by the group UNK_GreenSec. The attackers use trusted business workflows to make their approach seem legitimate, and the campaign differs from standard phishing by avoiding scare tactics and urgency.

Check Point stated, “ZipLine is another instance of how threat actors are increasingly banking on legitimate business workflows, such as approaching targets via a company’s Contact Us form on their website, thereby weaponizing trust in the process to sidestep any potential concerns.”

The campaign uses advanced tactics such as multi-stage delivery of malware, in-memory execution, and covert internet communication methods like DNS tunneling. The malicious files are often hosted on sub-domains of legitimate services such as Heroku, which provides computing infrastructure for web applications. These ZIP archives contain a Windows shortcut (LNK) that starts a PowerShell loader. This loader deploys the MixShell malware, enabling remote control, file operations, persistence on the system, and deeper network infiltration.

MixShell also comes in a variant with features to evade digital forensics and maintains its presence on infected systems through scheduled tasks. Not all files from the Heroku domains are harmful—malware delivery appears to be customized.

In many cases, the attackers use domains similar to those of legitimate, registered U.S. companies, building template websites to improve the campaign’s realism. According to Check Point, risks from the campaign include theft of intellectual property, ransomware, business email compromise, financial fraud, and broader supply chain disruptions.

- Advertisement -

Sergey Shykevich of Check Point Research emphasized, “Attackers are innovating faster than ever – blending human psychology, trusted communication channels, and timely AI-themed lures. To stay safe, organizations must adopt prevention-first, AI-driven defenses and build a culture of vigilance that treats every inbound interaction as a potential threat.”

For more details, see the full Check Point Research report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

Stay in the Loop

Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.

    1 Email per day. Unsubscribe at any time.

    - Advertisement -

    Latest News

    Citrix Patches Critical NetScaler RCE Flaw Amid Active Attacks

    Citrix addressed three security vulnerabilities in NetScaler ADC and NetScaler Gateway, one of which...

    CME XRP Futures Hit $1B Fastest Ever as Gemini Tops Coinbase App

    CME Group XRP futures reached $1 billion in open interest in just over three...

    Gemini Unveils XRP Mastercard: No New Perks, Just Blue Branding

    Gemini has released an "XRP Edition" of its credit card in partnership with Mastercard.The...

    Google Unveils Gemini 2.5 Flash Image to Rival OpenAI’s ChatGPT

    Google released Gemini 2.5 Flash Image, its latest AI tool for image generation and...

    Ethereum Hits New All-Time High as Stablecoin Growth Surges

    Ethereum reached an all-time high price of $4,946 on Sunday. The value of stablecoins on...

    Must Read

    5 Best Hacking eBooks for Beginners

    In this article we present the 5 Best Hacking eBooks for beginners as ranked by our editorial teamWelcome to the world of hacking, where...