ZgRAT malware delivery chain via Lovable-hosted invoice portals
Malware Activity
Summary
Hide ▲
Show ▼
A zgRAT malware delivery chain abused Lovable-hosted invoice portals to distribute a staged payload, increasing the chance that email recipients would run the trojanized software. The chain delivered RAR archives from Dropbox containing a legitimate signed executable and a trojanized DLL. That DLL launched DOILoader, which ultimately loaded zgRAT.
Related Happenings
WinRAR path traversal via Alternate Data Streams (CVE-2025-8088)
Vulnerability
H score21
First: 27.01.2026 21:38
Last: 27.01.2026 21:38
Sources 1
About this happening:
The CVE-2025-8088 WinRAR path traversal flaw is being actively exploited through Alternate Data Streams (ADS) to write malicious files outside the extraction direc...
WinRAR path traversal via Alternate Data Streams (CVE-2025-8088)
VulnerabilityAbout this happening: The CVE-2025-8088 WinRAR path traversal flaw is being actively exploited through Alternate Data Streams (ADS) to write malicious files outside the extraction direc...
BADAUDIO first-stage downloader activity
Malware Activity
H score43
First: 21.11.2025 12:42
Last: 21.11.2025 12:42
Sources 1
About this happening:
The BADAUDIO malware is now documented as a first-stage downloader that can decrypt and execute AES-encrypted payloads from a hard-coded C2 server, increasing the...
BADAUDIO first-stage downloader activity
Malware ActivityAbout this happening: The BADAUDIO malware is now documented as a first-stage downloader that can decrypt and execute AES-encrypted payloads from a hard-coded C2 server, increasing the...
Zimbra Collaboration Suite XSS flaw (CVE-2025-27915)
Vulnerability
H score47
First: 05.10.2025 17:45
Last: 05.10.2025 17:45
Sources 1
About this happening:
CVE-2025-27915 was exploited as a zero-day in Zimbra Collaboration Suite (ZCS 9.0, 10.0, and 10.1), exposing users to JavaScript execution inside authenticated web...
Zimbra Collaboration Suite XSS flaw (CVE-2025-27915)
VulnerabilityAbout this happening: CVE-2025-27915 was exploited as a zero-day in Zimbra Collaboration Suite (ZCS 9.0, 10.0, and 10.1), exposing users to JavaScript execution inside authenticated web...
Timeline
-
21.08.2025 01:11 1 articles · 10mo ago
Lovable-hosted invoice portals deliver zgRAT
Technical Analysis UpdateLovable-hosted invoice-portal links led to Dropbox-hosted RAR archives containing a legitimate signed executable and a trojanized DLL; the DLL launched DOILoader and ultimately loaded zgRAT. The activity was observed in email messages since February 2025 and described on August 20, 2025.
Show sources
- AI website builder Lovable increasingly abused for malicious activity — www.bleepingcomputer.com — 21.08.2025 01:11