Intel Utility Hijacked in AppDomain Attack to Launch Malware
ID: 2043e611-ea6e-59a8-b20e-94ee6e7ab67f
STIX ID: report--2043e611-ea6e-59a8-b20e-94ee6e7ab67f
Feed Name: GBHackers
Operation PhantomCLR is a sophisticated, targeted campaign that weaponizes a signed Intel utility (IAStorHelp.exe) by placing a malicious IAStorHelp.exe.config and unsigned .NET assemblies alongside it to hijack the AppDomainManager, enabling stealthy in-memory execution, JIT trampoline shellcode, AES-encrypted payloads, and CloudFront-backed C2; the report includes delivery details (spear-phishing ZIP with .lnk and decoy PDF), IOCs (SHA-256 hashes and domains), and defensive recommendations such as monitoring for unexpected .exe.config files, executions from user-writable directories, and unusual CloudFront HTTPS traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
