logo

Intel Utility Hijacked in AppDomain Attack to Launch Malware

ID: 2043e611-ea6e-59a8-b20e-94ee6e7ab67f

STIX ID: report--2043e611-ea6e-59a8-b20e-94ee6e7ab67f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Operation PhantomCLR is a sophisticated, targeted campaign that weaponizes a signed Intel utility (IAStorHelp.exe) by placing a malicious IAStorHelp.exe.config and unsigned .NET assemblies alongside it to hijack the AppDomainManager, enabling stealthy in-memory execution, JIT trampoline shellcode, AES-encrypted payloads, and CloudFront-backed C2; the report includes delivery details (spear-phishing ZIP with .lnk and decoy PDF), IOCs (SHA-256 hashes and domains), and defensive recommendations such as monitoring for unexpected .exe.config files, executions from user-writable directories, and unusual CloudFront HTTPS traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.