Proofpoint reported that threat actor TA555 used a previously unknown downloader called AdvisorsBot in malicious email campaigns targeting victims with hotel, restaurant, and telecommunications-themed lures. First observed in May 2018, the malware acted as an initial payload that contacted command-and-control infrastructure over HTTPS, retrieved a fingerprinting module, and profiled infected systems to identify higher-value targets for follow-on compromise.
Researchers said AdvisorsBot incorporated multiple anti-analysis features, including junk code, stack strings, API hashing, CRC32-based process and volume checks, virtual machine detection, and later machine SID blacklisting. Its modular design allowed operators to load DLLs or shellcode, and observed capabilities included screenshot capture, Outlook account collection, and broad host reconnaissance; by August, TA555 had also shifted to fileless shellcode execution and introduced a rewritten PowerShell/.NET variant, PoshAdvisor, while retaining the same command-and-control protocol and victim-fingerprinting behavior.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On August 15, the actor changed tactics again and delivered a PowerShell version of AdvisorsBot called PoshAdvisor. Proofpoint said the new variant preserved the same command-and-control protocol and fingerprinting behavior as AdvisorsBot.
In an August 8 campaign, the macro executed PowerShell that downloaded another PowerShell script, which ran embedded shellcode to execute AdvisorsBot without writing it to disk. The same version also added a machine SID blacklist anti-analysis check.
In the May and June 2018 campaigns, malicious documents used macros to execute PowerShell that downloaded and ran AdvisorsBot. This established the initial observed delivery chain for the malware family.
Proofpoint researchers first observed the previously undocumented AdvisorsBot downloader in malicious email campaigns beginning in May 2018. The campaigns used themed lures and primarily targeted hotel, restaurant, and telecommunications organizations.
Proofpoint documented AdvisorsBot as a previously unknown downloader malware family distributed by TA555 and described its anti-analysis, command-and-control, and fingerprinting-module behavior. The report also published indicators including command-and-control domains and IP addresses tied to the campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.