logo

Gh0st RAT and CloverPlus Adware Delivered Together in New Dual-Payload Malware Campaign

ID: c9786bd6-9417-5068-8a62-8be71e5f3ae1

STIX ID: report--c9786bd6-9417-5068-8a62-8be71e5f3ae1

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-20

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

This report describes a campaign using an obfuscated loader that embeds two encrypted payloads in its resources to deliver CloverPlus adware (wiseman.exe) and Gh0st RAT to the same host; the loader may copy itself to %temp%, decrypt and write a randomly named Gh0st RAT DLL to C:\, execute it via rundll32.exe, and establish persistence via Run registry keys and a malicious RemoteAccess service DLL. Researchers mapped the behavior to MITRE ATT&CK techniques and recommend monitoring rundll32 execution from unusual directories, Run key modifications, RemoteAccess service changes, %temp% executions, DNS anomalies, and sandbox-evasion indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.