Gh0st RAT and CloverPlus Adware Delivered Together in New Dual-Payload Malware Campaign
ID: c9786bd6-9417-5068-8a62-8be71e5f3ae1
STIX ID: report--c9786bd6-9417-5068-8a62-8be71e5f3ae1
Feed Name: cybersecurityNews.com
This report describes a campaign using an obfuscated loader that embeds two encrypted payloads in its resources to deliver CloverPlus adware (wiseman.exe) and Gh0st RAT to the same host; the loader may copy itself to %temp%, decrypt and write a randomly named Gh0st RAT DLL to C:\, execute it via rundll32.exe, and establish persistence via Run registry keys and a malicious RemoteAccess service DLL. Researchers mapped the behavior to MITRE ATT&CK techniques and recommend monitoring rundll32 execution from unusual directories, Run key modifications, RemoteAccess service changes, %temp% executions, DNS anomalies, and sandbox-evasion indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
