logo

Google Forms Job Lures Deliver PureHVNC in New Multi-Stage Malware Campaign

ID: 1c4ee065-da2c-54d3-b95c-d72cf8c61f1b

STIX ID: report--1c4ee065-da2c-54d3-b95c-d72cf8c61f1b

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Attackers are using convincing Google Forms and LinkedIn lures to distribute malicious ZIP files that ultimately deploy the PureHVNC .NET RAT. The multi-stage infection uses DLL hijacking (msimg32.dll), an obfuscated Python loader that runs Donut shellcode to inject into SearchUI.exe, and persistence via a registry Run key (CurrentVersion\Run\Miroupdate) and scheduled tasks; the campaign exfiltrates browser data, crypto wallets, and messaging app data. Observed indicators include C2 IP 207.148.66.14 (ports 56001–56003), mutex "Rluukgz", filenames like final.zip/config.log/image.mp3, and encoded PowerShell task creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.