PowMix Botnet Targets Czech Workforce with Malicious LNK Files
Rapid Read

PowMix Botnet Targets Czech Workforce with Malicious LNK Files

What's Happening? Cisco Talos has identified a botnet known as PowMix, which has been active since December 2025, targeting organizations in the Czech Republic. The infection process begins with malicious LNK files that activate a PowerShell loader, unpacking a ZIP archive and bypassing AMSI protect
Summarized by AI
AI Generated
This may include content generated using AI tools. Glance teams are making active and commercially reasonable efforts to moderate all AI generated content. Glance moderation processes are improving however our processes are carried out on a best-effort basis and may not be exhaustive in nature. Glance encourage our users to consume the content judiciously and rely on their own research for accuracy of facts. Glance maintains that all AI generated content here is for entertainment purposes only.