In a campaign FortiGuard Labs analyzed in April 2024, a fake shipment-delivery email carried an “invoice” SVG that created a ZIP archive and launched an obfuscated malware chain. The chain loaded VenomRAT and could deliver additional remote-access tools and a data stealer to Windows systems. FortiGuard’s report documents what its researchers observed then; it does not establish that the campaign or its indicators remain active today.
How the phishing attack works
The attack begins with an email claiming that a shipment has been delivered. Its attachment is an SVG named INV0ICE_#TBSBVS0Y3BDSMMX.svg, disguised as an invoice. According to FortiGuard Labs’ April 8, 2024 analysis, the SVG contains base64-encoded data and ECMAScript that creates a blob and downloads a ZIP archive named INV0ICE_#TBSBVS0Y3BDSMMX.zip.
The ZIP contains an obfuscated batch file with an embedded payload. FortiGuard attributes the batch-file obfuscation to BatCloak. The script copies a PowerShell execution file to C:UsersPublicxkn.exe, invokes it with hidden and noninteractive parameters, decodes data to pointer.png, and moves the resulting payload to C:UsersPublicLibrariespointer.cmd. Deliberate clutter in the batch file is intended to make analysis harder.
ScrubCrypt establishes the foothold
FortiGuard identifies pointer.cmd as a ScrubCrypt batch file. Its first payload establishes persistence and loads VenomRAT; a second attempts to bypass AMSI and ETW, Windows mechanisms commonly used to inspect or trace script and process activity.
#1 Best Overall
The report describes different persistence arrangements depending on privileges: a scheduled task named “OneNote 83701” for an administrator-level user, and a copy in the Startup folder for a user without administrator privileges.
Further payloads arrive through multiple routes
VenomRAT contacts a command-and-control (C2) server, sends details about the system, and can retrieve additional plugins. FortiGuard describes routes involving VBS scripts, Guloader PowerShell, steganographic JPG files, and process hollowing. These are alternative or additional plugin-delivery methods in the analysis, not steps that every infected system must follow in one fixed sequence.
What malware and data are involved
VenomRAT is the principal foothold in the documented chain, but it is not the only malware involved. FortiGuard reports the following tools and behaviors in the analyzed samples; findings about a particular sample should not be assumed to describe every version of a malware family.
| Malware or component | Behavior described in FortiGuard’s analysis |
|---|---|
| VenomRAT 6.0.3 | Remote access, persistent C2 communication, keylogging, and data-grabber functions. It sends system and user details, including hardware and operating-system information, camera availability, execution path, foreground window, and installed antivirus product. |
| NanoCore | A remote-access trojan delivered in the analysis through an obfuscated VBS route and additional stages. |
| XWorm | A remote-access trojan associated in the report with information theft; one route uses Guloader PowerShell and process hollowing. |
| Remcos | A remote-access trojan that the report says can capture keystrokes, screenshots, credentials, and other sensitive data. Multiple delivery methods were observed. |
| Stealer | Checks for selected cryptocurrency-wallet locations and Foxmail and Telegram data, then sends collected information to a C2 host. |
The combined risk is unauthorized remote access alongside collection of sensitive information. The exact activity depends on which payloads reach a system; FortiGuard’s report does not quantify victims, infections, financial losses, or campaign prevalence.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →What the published indicators can—and cannot—tell you
FortiGuard’s report includes six defanged C2 domains, four defanged URLs, and file hashes. Examples of the listed domains are hjkdnd[.]duckdns[.]org, mup830634[.]duckdns[.]org, and markjohnhvncpure[.]duckdns[.]org; listed URLs include nanoshield[.]pro and kisanbethak[.]com. Consult the primary report for the full indicator set.
These are indicators observed in an analysis published April 8, 2024, not confirmation that the domains or URLs are active or malicious now. Defanged indicators are deliberately altered to reduce the chance of accidental visits. Before using any indicator in a blocklist, investigation, or incident response, verify and handle it according to current threat-intelligence and organizational procedures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to reduce the risk
- Be wary of unexpected invoices and delivery notices. Treat an attachment as suspicious when you were not expecting it, particularly if it prompts you to open or extract a file. Verify the shipment through a known, separate channel rather than replying to the message.
- Do not open untrusted attachments. If a message seems suspicious, report it to your IT or security team using your organization’s established process.
- Monitor endpoints for suspicious execution and persistence. Security teams can investigate unexpected PowerShell and script activity, unusual files or scheduled tasks in user-writable locations, and signs of persistence or C2 communication. The paths and task name above are useful context for the specific 2024 analysis, not a complete detection rule.
- Use layered email and endpoint controls. FortiGuard recommends user vigilance, education, antivirus detection, monitoring, and content disarm and reconstruction (CDR). It says its antivirus detects and blocks the described samples and names FortiGate, FortiMail, FortiClient, and FortiEDR as products supporting that service. These are Fortinet’s claims; the report provides no independent comparison or quantified effectiveness across vendors.
- Check indicators against current intelligence. An old match can inform an investigation, but age and context matter. Validate the full indicator set against current sources before taking action.
For broader context, Dark Reading’s April 10, 2024 coverage quotes Fortinet senior antivirus analyst Cara Lin: “The attackers employ a variety of methods, including phishing emails with malicious attachments, obfuscated script files, and Guloader PowerShell, to infiltrate and compromise victim systems.” The coverage also quotes Lin noting that plugin delivery through different payloads highlights the campaign’s versatility.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors

