Workings of MalSync Malware Unveiled: DLL Hijacking & PHP Malware
ID: 0d26e964-5a7f-5583-841f-bbe709cc5b4b
STIX ID: report--0d26e964-5a7f-5583-841f-bbe709cc5b4b
Feed Name: GBHackers
Threat Score
This report analyzes the MalSync (DuckTail / SYS01) infostealer, detailing how malicious installers and EXEs drop PHP components and executables (e.g., wdelua.exe, php.exe, rhc.exe, ts.exe), establish persistence via scheduled tasks, perform DLL search-order hijacking, stage data via an index.php component, and communicate with a C2 server to receive instructions and exfiltrate stolen social media credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
