Google Forms Job Lures Deliver PureHVNC in New Multi-Stage Malware Campaign
ID: 1c4ee065-da2c-54d3-b95c-d72cf8c61f1b
STIX ID: report--1c4ee065-da2c-54d3-b95c-d72cf8c61f1b
Feed Name: cybersecurityNews.com
Attackers are using convincing Google Forms and LinkedIn lures to distribute malicious ZIP files that ultimately deploy the PureHVNC .NET RAT. The multi-stage infection uses DLL hijacking (msimg32.dll), an obfuscated Python loader that runs Donut shellcode to inject into SearchUI.exe, and persistence via a registry Run key (CurrentVersion\Run\Miroupdate) and scheduled tasks; the campaign exfiltrates browser data, crypto wallets, and messaging app data. Observed indicators include C2 IP 207.148.66.14 (ports 56001–56003), mutex "Rluukgz", filenames like final.zip/config.log/image.mp3, and encoded PowerShell task creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
