Malspam Campaign Abuses DoubleClick to Deploy Stealthy .NET Loader
ID: 064a324b-4743-5039-8295-3de1637e2de4
STIX ID: report--064a324b-4743-5039-8295-3de1637e2de4
Feed Name: GBHackers
A Huntress analysis details an active malspam campaign that leverages Google DoubleClick redirects and on-the-fly personalization to bypass email gateways and deliver a five-stage infection chain (HTML lure → JScript dropper → PowerShell stager → .NET loader → process-hollowed payload). The malware performs sandbox detection (including forcing reboots), patches AMSI and ETW, disables Defender, establishes NVIDIA-themed persistence, and communicates over AES-encrypted raw TCP to DDNS C2 servers; the report provides IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
