eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi.
The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-15, eSentire published technical analysis of TAG-150's evolving tradecraft, including details on DinDoor, DenoRAT, NightshadeC2, C2 infrastructure, and malware configuration artifacts. The report documented the previously observed June 2026 intrusion and its tooling.
After detecting the June 2026 intrusion, eSentire said its SOC isolated the affected host and helped the customer with remediation. This was the reported defensive response to the TAG-150 activity.
During the June 2026 intrusion, the attack chain used an apparently AI-generated PowerShell script named Griffin20.ps1 to install the Deno runtime, launch the Deno-based loader DinDoor, deploy DenoRAT, and then load NightshadeC2 through a PowerShell-delivered Python in-memory loader. eSentire also reported that DenoRAT supported capabilities including command execution, persistence, theft, remote control, and optional Chromium App-Bound Encryption bypass via DLL injection.
In June 2026, eSentire observed an intrusion in a finance customer environment where a ClickFix-style social engineering lure led to execution of a malicious command and MSI installer. The activity was attributed to TAG-150 and initiated a multi-stage malware chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.