Hackers Exploit AppDomain Hijacking To Weaponize Intel Utility
ID: 864c587c-7b02-5587-8ad0-52af64d16f8a
STIX ID: report--864c587c-7b02-5587-8ad0-52af64d16f8a
Feed Name: Cyber Press
Threat Score
A sophisticated malware campaign leverages a trusted Intel-signed executable and .NET AppDomainManager hijacking to load an obfuscated DLL delivered via a phishing ZIP/LNK. The threat uses JIT-based in-memory execution, long timing delays, encryption/obfuscation, CDN-hosted C2, reflective DLL loading, and anti-forensic measures to evade detection and hamper analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
