New Malware Campaign Delivers Gh0st RAT With CloverPlus Adware
ID: 557f3e49-59b4-51fd-8bdd-eea0276b4bc4
STIX ID: report--557f3e49-59b4-51fd-8bdd-eea0276b4bc4
Feed Name: Cyber Press
This Splunk Threat Research Team report describes a multi-payload campaign in which a sophisticated, obfuscated loader drops CloverPlus adware for monetization and decrypts/executes a Gh0st RAT DLL—using randomized paths and rundll32—to establish persistent, high-privilege backdoor access and keylogging. The report outlines loader mechanics, persistence methods (Run keys, installing as a service, remote service DLL), RDP monitoring, and detection recommendations focused on unusual rundll32 executions, suspicious registry modifications, and executions from %temp%.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
