Researchers Map Multilingual ZIP Phishing Campaigns Targeting Asian Organizations

Summary
Hunt.io researchers linked 28 Chinese-, English-, and Japanese-language phishing pages targeting organizations across Asia, finding shared templates, scripts, and ZIP/RAR lures themed around tax, finance, and government documents.
Key points
- The investigation identified 28 pages across three clusters: 12 Chinese-language, 12 English-language, and four Japanese-language pages.
- Shared webpage titles, scripts such as download.php and visitor_log.php, and hosting patterns suggest a reused toolkit or centralized builder.
- Pages use localized tax, payroll, finance, and government-document themes to lure visitors into downloading ZIP, RAR, or other archive files.
- The researchers linked the clusters to targeting across Taiwan, Hong Kong, Japan, and Southeast Asia; the article describes possible expansion from localized to multinational targeting.
- Some pages log visitor activity and dynamically reveal download links when a valid archive is available.
- The article recommends blocking identified domains, monitoring for reused scripts and infrastructure, filtering suspicious archive lures, and limiting execution of downloaded files.
Article Details
- Attack Vectors
- Multilingual phishing webpages use bureaucratic, payroll, tax, and finance-themed lures to persuade users to download ZIP/RAR archives.
- Download buttons and JavaScript reveal or update links to staged archive payloads, including links populated through download.php.
- The pages use visitor_log.php to record visitor activity; the article says this may include IP addresses or user-agent information.
- The article's background describes phishing emails impersonating Taiwan's Ministry of Finance and malicious PDFs containing embedded payload links.
- Defensive Notes
- Block the discovered phishing domains and monitor for newly observed domains with similar naming patterns.
- Query for phishing pages containing download.php or visitor_log.php and flag outbound HTTP requests to suspicious instances of those endpoints.
- Configure mail gateways to detect ZIP/RAR attachments with HR, tax, or finance-themed filenames.
- Sanitize downloaded or emailed archives before users access them, and limit execution of scripts or compressed files from email attachments or browsers.
- Conduct phishing-awareness training about fake official HR, finance, tax, and government document downloads.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 11c979baeb8bddc12e79ad4def0964e94[.]bulinouui[.]sbs | Campaign hostname serving a tax-penalty phishing archive lure. |
| DOMAIN | 199cb150cec25af3132ddd4e47b37248[.]bulinouui[.]sbs | Campaign hostname serving a tax-themed archive lure. |
| DOMAIN | 27160fcce1e199401dde5e01ce829006[.]ttcskhdl[.]lol | Campaign hostname serving a tax-themed archive lure. |
| DOMAIN | 3381536ffe13739277b0a87c08a66596[.]bulinouui[.]sbs | Campaign hostname serving a phishing archive lure. |
| DOMAIN | 5289c03d6d33ac4cf474de436f6bbf47[.]bulinouui[.]sbs | Campaign hostname serving a phishing archive lure. |
| DOMAIN | 53d9da1f7632f687dde3b0ec4df00710[.]bulinouui[.]sbs | Campaign hostname serving a phishing archive lure. |
| DOMAIN | 6358bdf15f655e7e305eacaf385cd12[.]bulinouui[.]sbs | Campaign hostname serving a phishing archive lure. |
| DOMAIN | cq1tw[.]icu | Campaign domain serving a phishing page linked to an application-platform archive lure. |
| DOMAIN | cq1tw[.]top | Campaign domain serving a regulatory-document phishing lure. |
| DOMAIN | gjqygs[.]cn | Campaign root domain identified as a phishing and central-hosting node. |
| DOMAIN | jpjpz1[.]cc | Campaign root domain hosting Japanese-language phishing lures. |
| DOMAIN | jpjpz1[.]top | Campaign domain serving a Japanese-language salary-themed phishing archive lure. |
| DOMAIN | jpjpz1[.]vip | Campaign domain serving a Japanese-language tax-themed phishing archive lure. |
| DOMAIN | jppjp[.]vip | Domain listed among infrastructure associated with the campaign clusters. |
| DOMAIN | qiqi1[.]xin | Campaign domain serving a Hong Kong finance-themed phishing archive lure. |
| DOMAIN | twmm[.]shop | Campaign domain serving a notification-letter phishing lure. |
| DOMAIN | twsw[.]cc | Campaign domain serving a phishing page linked to a tax-themed archive lure. |
| DOMAIN | twsww[.]xin | Campaign domain serving a Japanese-language salary-themed phishing archive lure. |
| DOMAIN | twswzz[.]icu | Campaign domain serving a business-registration phishing archive lure. |
| DOMAIN | twswzz[.]xin | Campaign domain serving a financial-themed phishing archive lure. |
| DOMAIN | vip[.]gaelh[.]cn | Campaign hostname serving a tax-filing phishing archive lure. |
| DOMAIN | www[.]bulinouui[.]sbs | Campaign hostname serving a tax-themed archive lure. |
| DOMAIN | www[.]wojkejys[.]lat | Campaign hostname serving a tax-compliance phishing archive lure. |
| DOMAIN | xinwenwamg[.]net | Campaign domain serving a phishing landing page. |
| DOMAIN | z2tw[.]vip | Campaign domain serving a phishing page linked to an import/export archive lure. |
| DOMAIN | z2tw[.]xin | Campaign domain serving a phishing page linked to an archive lure. |
| DOMAIN | zcqiyess[.]vip | Domain identified in the campaign's English-language phishing cluster. |
| DOMAIN | zxp0010w[.]vip | Campaign root domain hosting Chinese-language phishing lures. |
| IPV4 | 103[.]127[.]219[.]148 | IP listed for the campaign domain twsw[.]cc. |
| IPV4 | 154[.]205[.]139[.]195 | IP listed for the campaign domain jpjpz1[.]vip. |
| IPV4 | 154[.]205[.]139[.]223 | IP listed for the campaign domain jppjp[.]vip. |
| IPV4 | 38[.]54[.]1[.]105 | IP listed for the campaign domain cq1tw[.]icu. |
| IPV4 | 38[.]54[.]1[.]23 | IP listed for the campaign domain twmm[.]shop. |
| IPV4 | 38[.]54[.]107[.]103 | IP listed for the campaign domain twsww[.]xin. |
| IPV4 | 38[.]54[.]107[.]195 | IP listed for the campaign domain twswzz[.]xin. |
| IPV4 | 38[.]54[.]119[.]194 | IP listed for the campaign domain qiqi1[.]xin. |
| IPV4 | 38[.]54[.]16[.]25 | IP listed for the campaign domains z2tw[.]vip and xinwenwamg[.]net. |
| IPV4 | 38[.]54[.]16[.]254 | IP listed for the campaign domain z2tw[.]xin. |
| IPV4 | 38[.]54[.]17[.]132 | IP listed for the campaign domains zcqiyess[.]vip and vip.gaelh[.]cn. |
| IPV4 | 38[.]54[.]17[.]167 | Hosting IP associated with the English-cluster phishing domain gjqygs[.]cn. |
| IPV4 | 38[.]54[.]17[.]174 | IP listed for the campaign domain cq1tw[.]top. |
| IPV4 | 38[.]54[.]50[.]212 | Hosting IP associated with the Japanese-cluster phishing domain jpjpz1[.]cc. |
| IPV4 | 38[.]54[.]88[.]103 | IP listed for the campaign domain jpjpz1[.]top. |
| IPV4 | 38[.]54[.]88[.]44 | Hosting IP associated with the Chinese-cluster phishing domain zxp0010w[.]vip. |
| IPV4 | 38[.]60[.]199[.]26 | IP listed for the campaign domain twswzz[.]icu. |
| URL | hxxp[:]//199cb150cec25af3132ddd4e47b37248[.]bulinouui[.]sbs | Campaign phishing page serving a tax-return archive lure. |
| URL | hxxp[:]//27160fcce1e199401dde5e01ce829006[.]ttcskhdl[.]lol | Campaign phishing page serving a tax-return archive lure. |
| URL | hxxp[:]//3381536ffe13739277b0a87c08a66596[.]bulinouui[.]sbs | Campaign phishing page serving an archive lure. |
| URL | hxxp[:]//53d9da1f7632f687dde3b0ec4df00710[.]bulinouui[.]sbs | Campaign phishing page serving an archive lure. |
| URL | hxxp[:]//twmm[.]shop | Phishing page serving a notification-letter archive lure. |
| URL | hxxp[:]//twswzz[.]icu | Phishing page serving a business-registration archive lure. |
| URL | hxxp[:]//twswzz[.]xin | Phishing page serving a financial-confirmation archive lure. |
| URL | hxxp[:]//www[.]wojkejys[.]lat | Campaign phishing page serving a tax-compliance archive lure. |
| URL | hxxps[:]//11c979baeb8bddc12e79ad4def0964e94[.]bulinouui[.]sbs | Campaign phishing page serving a tax-penalty archive lure. |
| URL | hxxps[:]//5289c03d6d33ac4cf474de436f6bbf47[.]bulinouui[.]sbs | Campaign phishing page serving an archive lure. |
| URL | hxxps[:]//6358bdf15f655e7e305eacaf385cd12[.]bulinouui[.]sbs/?1d794ebf8cc16e0770adc215e34d26a0 | Campaign phishing URL serving an archive lure. |
| URL | hxxps[:]//cq1tw[.]icu/index[.]html | Phishing page serving an application-platform archive lure. |
| URL | hxxps[:]//cq1tw[.]top/index[.]html | Phishing page serving a regulatory-document archive lure. |
| URL | hxxps[:]//jpjpz1[.]top/index[.]html | Phishing page serving a Japanese-language salary-themed archive lure. |
| URL | hxxps[:]//jpjpz1[.]vip | Phishing page serving a Japanese-language tax-themed archive lure. |
| URL | hxxps[:]//qiqi1[.]xin/index[.]html | Phishing page serving a Hong Kong finance-themed archive lure. |
| URL | hxxps[:]//twsw[.]cc/download[.]html | Phishing page serving a tax-invoice archive lure. |
| URL | hxxps[:]//twsww[.]xin/index[.]html | Phishing page serving a Japanese-language salary-themed archive lure. |
| URL | hxxps[:]//vip[.]gaelh[.]cn | Campaign phishing page serving a tax-filing archive lure. |
| URL | hxxps[:]//www[.]bulinouui[.]sbs | Campaign phishing page serving a tax-return archive lure. |
| URL | hxxps[:]//xinwenwamg[.]net/index[.]html | Campaign phishing landing page. |
| URL | hxxps[:]//z2tw[.]vip/index[.]html | Phishing page serving an import/export archive lure. |
| URL | hxxps[:]//z2tw[.]xin | Phishing page serving an archive lure. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe article maps benign-sounding HR, tax, and finance filenames used for archive lures to this technique.T1071.001 · Web ProtocolsThe article associates visitor_log.php and download.php communication and payload control with HTTP(S) web traffic.T1102 · Web ServiceThe article maps centralized infrastructure serving multilingual phishing pages with shared script logic to this technique.T1113 · Screen CaptureThe article states visitor_log.php likely records visitor IPs, user agents, and session details for tracking.T1204.002 · Malicious FileThe article describes victims manually executing downloaded archives containing staged malware droppers.T1566.002 · Spearphishing LinkPhishing webpages prompt users to click download buttons that initiate ZIP/RAR payload downloads.T1583.001 · DomainsThe article says multiple domains were registered for phishing distribution.T1584.001 · DomainsThe article maps deployment of phishing kits on reused or compromised web-service infrastructure to this technique.T1592 · Gather Victim Host InformationThe article maps targeting of specific regions and finance/government sectors to reconnaissance before the campaign.T1593 · Search Open Websites/DomainsThe article maps use of regional trust-themed web templates and multiple domains to searching open websites or domains.
Malware
GobRATflagged in threat intelligence sources with one warning linked to the "Bulbature, beneath the waves of GobRAT" campaign.HoldingHandsIn early 2025, FortiGuard Labs documented a coordinated, multi-stage campaign that evolved from the deployment of Winos 4.0 in Taiwan to the distribution of the HoldingHands malware family across East and Southeast Asia.Winos 4.0In early 2025, FortiGuard Labs documented a coordinated, multi-stage campaign that evolved from the deployment of Winos 4.0 in Taiwan to the distribution of the HoldingHands malware family across East and Southeast Asia.
Vendors
Tools
Countries
ChinaShift from localized to multinational targeting, expanding from Taiwan, Indonesia, and China to Japan and Southeast Asia.Hong Kongfollowed by Japanese, which strongly suggests an organized operation targeting users across Taiwan, Hong Kong, and Japan.IndonesiaShift from localized to multinational targeting, expanding from Taiwan, Indonesia, and China to Japan and Southeast Asia.JapanShift from localized to multinational targeting, expanding from Taiwan, Indonesia, and China to Japan and Southeast Asia.Malaysiaextending from Mainland China (March 2024) to Taiwan and Japan (January-March 2025), and most recently, Malaysia. The campaigns relied on fake government or corporate documents such as tax regulations, salarySingaporewhich, according to Hunt.io, is hosted by Kaopu Cloud HK Limited under ASN AS138915, and is located in Singapore. The host exposes multiple open services, including SSH (port 22) running OpenBSD OpenSSH 8.9p1 onTaiwanShift from localized to multinational targeting, expanding from Taiwan, Indonesia, and China to Japan and Southeast Asia.
Industries
corporateand uncover how a single infrastructure supports a broad-spectrum phishing ecosystem targeting corporate, governmental, and financial entities throughout Asia.financialand Southeast Asia use multilingual ZIP file lures and shared web templates to target government and financial organizations. These operations are characterized by multilingual web templates, region-specificGovernmentacross East and Southeast Asia use multilingual ZIP file lures and shared web templates to target government and financial organizations. These operations are characterized by multilingual web templates,