Researchers detailed a multi-stage malware campaign that used fake trading software installers to deliver MineBridge RAT, including a trojanized TradingView Desktop package served from the look-alike domain tradingview[.]cyou. The malicious Windows installer, signed by YUNIVELL, LLC, selectively targeted Windows 10 systems and launched PowerShell-based stages that installed and configured OpenSSH, retrieved attacker-controlled keys and configuration, and established a reverse SSH tunnel to 86.106.181[.]183:32672 to maintain remote access. The operation also relied on shortened URLs and additional lures such as Bitcoin_Trade.exe, Arbitrage_Bot.exe, and Polarr_Setup (2).exe.
Follow-on stages created scheduled tasks disguised as OneDrive Sync and Google Disk Sync to fetch more PowerShell payloads, eventually deploying NetSupport client components and MineBridge RAT. The malware chain abused TeamViewer for DLL side-loading, giving operators persistent control while blending into legitimate remote administration activity. Reporting indicates the campaign reflects a sophisticated delivery mechanism built to evade suspicion by impersonating trusted trading tools and layering multiple persistence and remote-access techniques.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz reported that it uncovered the full multi-stage MineBridge RAT attack chain in May 2021, documenting the installer, PowerShell stages, reverse SSH tunnel, and final payloads.
Threat actors registered the impersonation domain tradingview[.]cyou to mimic tradingview[.]com and support delivery of a fake TradingView installer.
Threat actors began distributing MineBridge RAT with an updated delivery mechanism in March 2021, using trading-themed lures and multi-stage malware installation.
MineBridge RAT was first discovered in January 2020 targeting financial services organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.