Threat actors distributed a trojanized Windscribe VPN installer that paired the legitimate application with malicious components to covertly infect Windows systems. The package dropped the real VPN installer alongside a malicious executable, lscm.exe, and a VBS launcher, win.vbs, so the visible software installation could conceal background malware activity. Trend Micro reported that the installer was obtained from fraudulent sources rather than Windscribe’s official download channels or legitimate app stores.
During execution, the malware retrieved an encrypted payload named Dracula.jpg, passed it through multiple layers of obfuscation and decryption, and installed Backdoor.MSIL.BLADABINDI.THA. The backdoor gave attackers the ability to download, execute, and update files, capture screenshots, and collect host details including the machine name, operating system, username, and installed antivirus products, providing broad remote access and reconnaissance capability on compromised hosts.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that threat actors were distributing a bundled Windscribe VPN installer from fraudulent sources that also dropped malicious files, including lscm.exe and win.vbs, to install a BLADABINDI backdoor. The report also published technical details and indicators of compromise for the payload delivery chain, including Dracula.jpg and related infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.