Friday, September 4, 2026

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as “Cascading Shadows” to deliver various malware, including Agent Tesla, XLoader, and Remcos RAT.

The attackers’ strategy hinges on using multiple, seemingly simple but strategically layered stages, which not only evade traditional sandbox environments but also complicates analysis by cybersecurity experts.

The Deceptive Prelude

The campaign begins with phishing emails disguised as official communications, typically claiming a new payment has been made.

These emails contain a compressed file named “doc00290320092.7z”, directing the victim to review an ‘order file’.

Cascading Shadows
 Attack chain used for this campaign.

Once opened, the .7z file reveals a JavaScript encoded (.jse) file. This initial file acts as a downloader, fetching a PowerShell script from a remote server, initiating the infection chain.

Unraveling the Layers

The PowerShell script, devoid of heavy obfuscation, hosts a Base64-encoded payload which is decoded, saved to disk, and executed.

Interestingly, subsequent analysis has revealed that the payload varies, choosing between either a .NET or an AutoIt compiled executable.

According to the Report, this bifurcation in the attack chain allows the malware to adapt, choosing between paths to increase infection success.

The .NET executable decrypts the payload, either with AES or Triple DES, before injecting it into a running RegAsm.exe process.

Similarities found in multiple .NET samples from this campaign indicate a deliberate design to inject different malware families, like Agent Tesla or XLoader, into running processes, leveraging the same underlying infection method.

On the other alternative path, AutoIt executables introduce an additional layer of complexity.

They contain encrypted payloads that load shellcode, which, once decrypted, injects the final malware into a RegSvcs process.

This AutoIt script’s role also includes running malicious code through DLLCALLADDRESS references, posing challenges for analysis.

Despite the attackers’ intricate strategies, security solutions like Advanced WildFire can detect each stage of the Cascading Shadows attack chain.

Cascading Shadows
AutoIt script extracted by WildFire.

Palo Alto Networks’ Advanced URL Filtering, Advanced DNS Security, and Cortex XDR with XSIAM provide layered defenses against these threats.

For organizations potentially compromised, immediate contact with Unit 42 Incident Response is recommended.

This attack chain highlights a continuing trend in cyber threats, where attackers rely on complexity and variety rather than sophisticated obfuscation to evade detection.

The analyzed techniques offer crucial insights for enhancing threat hunting capabilities, particularly in dealing with AutoIt-based malware and debugging shellcode.

This analysis underscores the perpetual cat-and-mouse game between cyber defenders and attackers, showcasing the need for constant vigilance and advanced detection capabilities.

Indicators of Compromise

AutoIt Infection Chain 1

SHA-256 HashDescription
00dda3183f4cf850a07f31c776d306438b7ea408e7fb0fc2f3bdd6866e362ac5doc00290320092.7z
f4625b34ba131cafe5ac4081d3f1477838afc16fedc384aea4b785832bcdbfdddoc00290320092.jse
d616aa11ee05d48bb085be1c9bad938a83524e1d40b3f111fa2696924ac004b2files.catbox[.]moe/rv94w8[.]ps1
550f191396c9c2cbf09784f60faab836d4d1796c39d053d0a379afaca05f8ee8AutoIt compiled EXE (Agent Tesla variant)

AutoIt Infection Chain 2

SHA-256 HashDescription
61466657b14313134049e0c6215266ac1bb1d4aa3c07894f369848b939692c49doc00290320092.7z
7fefb7a81a4c7d4a51a9618d9ef69e951604fa3d7b70d9a2728c971591c1af25doc00290320092.jse
8cdb70f9f1f38b8853dfad62d84618bb4f10acce41e9f0fddab422c2c253c994files.catbox[.]moe/gj7umd[.]ps1
c93e37e35c4c7f767a5bdab8341d8c2351edb769a41b0c9c229c592dbfe14ff2AutoIt compiled EXE (Agent Tesla variant)

Agent Tesla (Variant) Configuration

FieldValue
FTP Serverftp[:]//ftp.jeepcommerce[.]rs
FTP Usernamekel-bin@jeepcommerce[.]rs
FTP PasswordJhrn)GcpiYQ7

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft

A major upgrade to the Python-based NodeStealer malware, transforming...

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams...

MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution

A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled...

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in...

Related Articles

Recent News