Researchers documented two financially motivated malware operations using multi-stage delivery chains built around JavaScript and MSI installers. One campaign linked to QakBot used search-engine pay-per-click malvertising and fake TeamViewer and Zoom installers, with redirect infrastructure including acehphonnajaya.com, homepagego.com, and bobforlacitycouncil.com, ultimately leading to an MSI payload hosted at richtools.info and 216.120.201.170. Analysis of the MSI found a QakBot stager with a modified configuration-decoding and C2 parsing routine, including an added flag field in C2 entries, suggesting the operators were testing or expanding malvertising as a delivery method.
Proofpoint separately tracked TA866 in a campaign dubbed Screentime, targeting organizations in the United States and Germany through email attachments and URLs routed via the 404 TDS traffic distribution system. Its infection chain also relied on a JavaScript downloader and MSI package, which installed a VBS downloader called WasabiSeed that maintained persistence and fetched additional payloads. TA866 distinguished itself by deploying a Screenshotter tool to capture victims’ desktops for manual triage before selectively delivering follow-on malware, including an AutoHotKey-based AHK Bot for Active Directory profiling and in-memory Rhadamanthys Stealer, highlighting a broader criminal trend of using staged MSI-based infections to qualify victims before deeper compromise.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed additional German-language TA866 emails on January 24, 2023. This reinforced the actor's sporadic targeting of recipients in Germany.
Proofpoint reported that domains used in the January 23–24, 2023 campaign were registered on the day of the campaign after expired domains were re-sold. The infrastructure included about 20 domains and multiple redirect stages through 404 TDS.
On January 23–24, 2023, Proofpoint observed a large TA866 campaign sending tens of thousands of emails to more than a thousand organizations. The emails used thread hijacking and a 'check my presentation' lure.
Proofpoint observed sporadic TA866 targeting in Germany, including German-language emails sent on December 8, 2022. This marked documented expansion beyond primarily U.S.-focused targeting.
Proofpoint reported first observing the financially motivated TA866 activity cluster, which it dubbed 'Screentime,' in October 2022. The campaigns used email-delivered malicious attachments or URLs and primarily targeted organizations in the United States.
Proofpoint said the traffic distribution system '404 TDS' had been tracked since at least September 2022 and was used to route victims in multiple phishing and malware campaigns. It assessed the TDS was likely a shared or sold tool.
The Walmart Global Tech post published indicators of compromise tied to the suspected campaign, including richtools.info, 216.120.201.170, related JavaScript hashes, and MSI hash 72cef301ca25db6f1aa42f9380ab12ae2e99a725. The report also tied related infrastructure such as acehphonnajaya.com, homepagego.com, and bobforlacitycouncil.com to redirect chains and lure delivery.
Analysis of an MSI payload delivered from richtools.info found a QakBot stager with slightly modified configuration decoding and C2 parsing, including an added flag field in C2 entries. The extracted configuration also contained a large list of C2 nodes and CONF1 values including 10=BB12 and 3=1675090602.
A Walmart Global Tech researcher analyzed a suspected QakBot malvertising operation using pay-per-click search ads and software-themed lures to distribute malware. The investigation linked JavaScript downloaders, redirect infrastructure, and MSI payloads to possible QakBot delivery via malvertising.
Proofpoint published analysis describing TA866's JavaScript-to-MSI infection chain, the WasabiSeed VBS downloader, and a dedicated Screenshotter payload used to capture and exfiltrate victim desktop images before follow-on malware deployment. The report said activity had been observed from October 2022 through at least January 2023.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 165 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.