Skip to main content
Mallory
1 malware family

ZipLine

Also known aszipline

ZipLine is a phishing campaign described by Check Point Research in late 2025. According to the provided content, the campaign shifted focus to Europe and used HR-themed lures targeting organizations in the UK, Poland, Italy, and the Czech Republic. The attacker was reported to initiate contact through victims’ public "Contact Us" forms. The campaign used newer iterations of MixShell and relied largely or almost entirely on herokuapp domains for command-and-control. The German-language context states that ZipLine targeted critical manufacturing and export-oriented mid-sized companies. No high-confidence attribution to a specific threat actor or nation state is provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Capital Goods

Where they target

Geographies tied to known operations.

  • 🇦🇹 Austria
  • 🇨🇭 Switzerland
MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.006
Web Services
TA0001
Initial Access
2 techniques
T1078×2
Valid Accounts
T1566×2
Phishing
T1566.001×2
Spearphishing Attachment
TA0003
Persistence
1 technique
T1078×2
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
1 technique
T1078×2
Valid Accounts
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

IOCS

Observables

7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables7

Domains, IPs, and hashes tied to this actor, refreshed continuously.