logo

New Malware Campaign Delivers Gh0st RAT With CloverPlus Adware

ID: 557f3e49-59b4-51fd-8bdd-eea0276b4bc4

STIX ID: report--557f3e49-59b4-51fd-8bdd-eea0276b4bc4

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Varshini

...
...

This Splunk Threat Research Team report describes a multi-payload campaign in which a sophisticated, obfuscated loader drops CloverPlus adware for monetization and decrypts/executes a Gh0st RAT DLL—using randomized paths and rundll32—to establish persistent, high-privilege backdoor access and keylogging. The report outlines loader mechanics, persistence methods (Run keys, installing as a service, remote service DLL), RDP monitoring, and detection recommendations focused on unusual rundll32 executions, suspicious registry modifications, and executions from %temp%.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.