PowMix Botnet Targets Czech Organizations with Malicious LNK Files

PowMix Botnet Targets Czech Organizations with Malicious LNK Files

First seen 17 Apr 2026, 20:08 UTC Blog.TalosintelligenceSocprimeScworld 83% similarity 72.5

Article Content

Browse articles
ThreatCluster

The PowMix botnet has been identified as targeting Czech organizations since at least December 2025. Attackers use malicious LNK files to initiate a PowerShell loader that extracts a ZIP archive, bypasses AMSI protections, and executes the PowMix payload directly in memory. The campaign employs tactics similar to the earlier ZipLine campaign, including ZIP-based payload concealment and the use of herokuapp.com for command-and-control infrastructure. The malware maintains persistence through a scheduled task with a randomized name and utilizes a global mutex for execution control. Cisco Talos has documented the botnet's capabilities, including remote command execution and self-removal features. Organizations are advised to implement strict controls on LNK file execution and monitor for suspicious PowerShell activity. Detection measures have been enhanced with new signatures for ClamAV and Snort. The full scope of impact remains unclear as the final payload has not been observed.

Key Points: • PowMix botnet targets Czech organizations using malicious LNK files. • The attack method includes a PowerShell loader that bypasses AMSI protections. • Organizations should enforce strict controls on LNK file execution and monitor PowerShell activity.

ThreatCluster AI

Timeline

2025-08-01
ZipLine campaign reported by Check Point.
2025-12-01
PowMix botnet activity begins targeting Czech organizations.
2026-04-16
Talos publishes findings on PowMix botnet.
2026-04-17
Socprime reports on PowMix botnet activity.

Community

Browse all →