: The final stage usually installs a RAT (such as Micropsia), allowing attackers to: Exfiltrate documents and browser data. Take screenshots. Record audio or keystrokes. 4. Technical Indicators (Typical) File Type 7-Zip Archive (LZMA/LZMA2 compression) Common Target Government, media, and diplomatic sectors Attribution Gaza Cybergang (Group196 / MoleRATS) 5. Mitigation & Recommendations To defend against this and similar threats:
: The filename suggests a video compilation of football highlights, a highly effective "click-bait" strategy during or after major sports tournaments.
: Windows shortcut files masquerading as video files. WorldCupHighlights2.7z
The file WorldCupHighlights2.7z is a compressed archive used as a delivery mechanism for malware. It exploits the high interest in the FIFA World Cup to lure users into downloading and executing malicious payloads. Historically, this file has been associated with Palestinian-aligned threat actors targeting regional entities through social engineering. 2. Delivery & Social Engineering
The file is a known malicious archive used in cyberattacks, specifically linked to campaigns by threat actors like GPC (Gaza Cybergang) . These attackers frequently use lures related to major sporting events to trick victims into downloading malware. : The final stage usually installs a RAT
: Educate staff on the risks of "too good to be true" lures, even if they appear to be related to current news or sports.
: Configure email gateways to block or quarantine .7z , .rar , and .iso files from external sources. : Windows shortcut files masquerading as video files
: Executing the LNK file often triggers a background script.