logo

Workings of MalSync Malware Unveiled: DLL Hijacking & PHP Malware

ID: 0d26e964-5a7f-5583-841f-bbe709cc5b4b

STIX ID: report--0d26e964-5a7f-5583-841f-bbe709cc5b4b

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2024-03-20

Date Updated: 2026-04-22

Author: Eswar

...
...

This report analyzes the MalSync (DuckTail / SYS01) infostealer, detailing how malicious installers and EXEs drop PHP components and executables (e.g., wdelua.exe, php.exe, rhc.exe, ts.exe), establish persistence via scheduled tasks, perform DLL search-order hijacking, stage data via an index.php component, and communicate with a C2 server to receive instructions and exfiltrate stolen social media credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.