Hackers Use AppDomain Hijacking to Turn Trusted Intel Utility Into Malware Launcher
ID: 526378a3-39ce-5c48-b8fa-eb8b07744a8d
STIX ID: report--526378a3-39ce-5c48-b8fa-eb8b07744a8d
Feed Name: cybersecurityNews.com
Operation PhantomCLR is a highly stealthy attack campaign that weaponizes a signed Intel utility by placing a malicious .exe.config to hijack .NET AppDomainManager, causing a rogue DLL (IAStorHelpMosquitoproof.dll) to load before the legitimate binary runs. Delivered via spear-phishing ZIPs with disguised shortcuts targeting organizations in the Middle East and EMEA financial sectors, the framework uses extensive sandbox-evasion (CPU burn and iterative key derivation), JIT trampoline in-memory shellcode execution, DLL injection noise, domain-fronted C2 through CloudFront, and memory cleanup to frustrate detection and forensics; affected systems should be treated as fully compromised and remediated accordingly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
