MixShell Malware Targets U.S. Manufacturers in ZipLine Attack

Supply Chain Manufacturers Targeted by ZipLine Campaign Using MixShell Malware and AI-Themed Social Engineering

  • Attackers are targeting supply chain-related manufacturing companies using an in-memory Malware called MixShell.
  • The campaign, identified as ZipLine, uses professional conversations through company contact forms instead of typical phishing emails.
  • Targets include industrial manufacturing, hardware, biotechnology, and other critical sectors in the U.S., Singapore, Japan, and Switzerland.
  • The attack uses multi-stage payloads and blends in with usual business operations by leveraging trusted communication channels and Artificial Intelligence (AI) themes.
  • Experts warn that the campaign can lead to theft, Ransomware, financial fraud, and major supply chain disruptions.

Cybersecurity researchers have reported a new campaign called ZipLine targeting key supply chain manufacturing companies with the MixShell malware. The campaign, mainly affecting U.S. entities as well as organizations in Singapore, Japan, and Switzerland, relies on social engineering and avoids common phishing methods by initiating contact through public “Contact Us” forms on company websites.

- Advertisement -

According to Check Point Research, attackers establish multi-week conversations that appear credible and may include fake non-disclosure agreements (NDAs). After building trust, they deliver a ZIP file containing MixShell, a stealthy malware that operates in the memory of infected computers and is not stored on disk, which helps avoid detection.

The targeted companies operate in sectors such as machinery, metalwork, hardware, semiconductors, consumer goods, biotechnology, and pharmaceuticals. Check Point has found connections between digital certificates used in this campaign and infrastructure previously linked to TransferLoader attacks by the group UNK_GreenSec. The attackers use trusted business workflows to make their approach seem legitimate, and the campaign differs from standard phishing by avoiding scare tactics and urgency.

Check Point stated, “ZipLine is another instance of how threat actors are increasingly banking on legitimate business workflows, such as approaching targets via a company’s Contact Us form on their website, thereby weaponizing trust in the process to sidestep any potential concerns.”

The campaign uses advanced tactics such as multi-stage delivery of malware, in-memory execution, and covert internet communication methods like DNS tunneling. The malicious files are often hosted on sub-domains of legitimate services such as Heroku, which provides computing infrastructure for web applications. These ZIP archives contain a Windows shortcut (LNK) that starts a PowerShell loader. This loader deploys the MixShell malware, enabling remote control, file operations, persistence on the system, and deeper network infiltration.

- Advertisement -

MixShell also comes in a variant with features to evade digital forensics and maintains its presence on infected systems through scheduled tasks. Not all files from the Heroku domains are harmful—malware delivery appears to be customized.

In many cases, the attackers use domains similar to those of legitimate, registered U.S. companies, building template websites to improve the campaign’s realism. According to Check Point, risks from the campaign include theft of intellectual property, ransomware, business email compromise, financial fraud, and broader supply chain disruptions.

Sergey Shykevich of Check Point Research emphasized, “Attackers are innovating faster than ever – blending human psychology, trusted communication channels, and timely AI-themed lures. To stay safe, organizations must adopt prevention-first, AI-driven defenses and build a culture of vigilance that treats every inbound interaction as a potential threat.”

For more details, see the full Check Point Research report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

BTC Rally Tops $91K as $64.2M Shorts Are Liquidated in 24hrs

Bitcoin topped $91,000 on Saturday as short-covering drove much of the move.About $64.2 million...

Bitcoin Tops $91K as Liquidations, Venezuela News Spur Rally

Bitcoin climbed above $91,000 on Sunday as a broad token rebound extended into early...

Hut 8 expands Coinbase credit to $200M, AI deal lifts rally!

Hut 8 expanded a credit facility with Coinbase to $200 million.The company said it...

Warren Buffett Steps Down as CEO; Greg Abel Takes Helm Ahead

Warren Buffett has stepped down as CEO of Berkshire Hathaway, with his final working...

Quantum Solutions posts $4.71M unrealized ETH holdings loss.

Quantum Solutions bought about $20.6 million of Ethereum, holding roughly 5,030 ETH on its...
- Advertisement -

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Bitcoin (BTC) $ 91,389.00 1.53%
Ethereum (ETH) $ 3,147.99 1.16%
XRP (XRP) $ 2.07 1.11%
Bittensor (TAO) $ 258.42 0.56%
Polkadot (DOT) $ 2.14 0.36%
Cardano (ADA) $ 0.396503 0.39%
Chainlink (LINK) $ 13.38 1.32%
Hyperliquid (HYPE) $ 25.22 2.42%
Monero (XMR) $ 435.61 0.49%
Hedera (HBAR) $ 0.122449 0.85%
Toncoin (TON) $ 1.86 2.75%