logo

Hackers Exploit AppDomain Hijacking To Weaponize Intel Utility

ID: 864c587c-7b02-5587-8ad0-52af64d16f8a

STIX ID: report--864c587c-7b02-5587-8ad0-52af64d16f8a

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Varshini

...
...

A sophisticated malware campaign leverages a trusted Intel-signed executable and .NET AppDomainManager hijacking to load an obfuscated DLL delivered via a phishing ZIP/LNK. The threat uses JIT-based in-memory execution, long timing delays, encryption/obfuscation, CDN-hosted C2, reflective DLL loading, and anti-forensic measures to evade detection and hamper analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.