Gh0st RAT, CloverPlus Hit Victims in Dual-Malware Campaign
ID: 639e29d9-5fc0-561b-956f-d66435a9adc3
STIX ID: report--639e29d9-5fc0-561b-956f-d66435a9adc3
Feed Name: GBHackers
This Splunk Threat Research Team analysis describes a dual-payload campaign that bundles CloverPlus adware for monetization with a Gh0st RAT backdoor for long-term remote access. An obfuscated loader drops two encrypted resources, copies itself to %temp% to evade path-based detection, decrypts and executes the RAT via rundll32, and employs multiple evasive and persistence techniques — including token privilege escalation, DNS hijacking, ping-based sandbox delays, VM checks with a dead-drop resolver, keylogging of RDP sessions, and service/registry persistence — with corresponding detection guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
