Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

ZipWhisper

ZipWhisper is a PowerShell-based stealer used by the hacktivist threat actor Punishing Owl in campaigns targeting Russian organizations, including state institutions, scientific enterprises, IT organizations, government security agencies, and broader critical infrastructure targets. Observed since at least December 2025, it has been delivered via phishing and BEC-style emails containing password-protected ZIP archives with disguised Windows shortcut (LNK) files masquerading as PDF documents. When opened, the LNK executes PowerShell commands that download ZipWhisper from attacker-controlled infrastructure, including a command-and-control server at bloggoversikten[.]com. ZipWhisper harvests sensitive data from infected Windows systems, specifically browser credential files, cookies, and saved passwords. It stages the stolen data in the AppData/Local/Temp directory, packages it into ZIP archives using filenames that include the username and chunk numbers, and uploads the archives back to the attacker-controlled server via a customized endpoint structure. Supporting reporting also states that the malware was used to harvest sensitive data and upload it to the same remote server, and that data stolen in related operations was later leaked by Punishing Owl on the dark web. Analysis of the script identified code comments suggesting possible use of AI tooling to generate parts of the malware.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Punishing Owl

...download a stealer named ZipWhisper from a remote server to harvest sensitive data and upload it to the same server.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1059.001PowerShellEvidence1

"Opening the LNK file results in the execution of a PowerShell command to download a stealer named ZipWhisper..."

T1204User ExecutionEvidence1

"...embed links that, when clicked, lead to the download of a malicious loader..."

Stealth

1 technique
T1036MasqueradingEvidence1

"...contains a Windows shortcut (LNK) masquerading as a PDF document."

Collection

1 technique
T1560Archive Collected DataEvidence1

"...phishing emails with a password-protected ZIP archive..."

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

"...lead to the download of a malicious loader... Download the NetSupport RAT from one of the several external domains..."; "...PowerShell command to download a stealer named ZipWhisper from a remote server..."

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

"...download a stealer named ZipWhisper... to harvest sensitive data and upload it to the same server."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.