logo

Malspam Campaign Abuses DoubleClick to Deploy Stealthy .NET Loader

ID: 064a324b-4743-5039-8295-3de1637e2de4

STIX ID: report--064a324b-4743-5039-8295-3de1637e2de4

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Eswar

...
...

A Huntress analysis details an active malspam campaign that leverages Google DoubleClick redirects and on-the-fly personalization to bypass email gateways and deliver a five-stage infection chain (HTML lure → JScript dropper → PowerShell stager → .NET loader → process-hollowed payload). The malware performs sandbox detection (including forcing reboots), patches AMSI and ETW, disables Defender, establishes NVIDIA-themed persistence, and communicates over AES-encrypted raw TCP to DDNS C2 servers; the report provides IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.