logo

Operation DualScript Bypasses Defenses to Hijack Crypto and Cash

ID: cfa3eccf-9b73-52c0-8c1a-7c109c7b9313

STIX ID: report--cfa3eccf-9b73-52c0-8c1a-7c109c7b9313

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Operation DualScript is a sophisticated, multi-stage in-memory malware campaign that establishes persistence via Windows Scheduled Tasks to run two parallel chains: a PowerShell-based clipboard hijacker that replaces copied cryptocurrency addresses and a RetroRAT implant providing keystroke capture and remote control; the campaign targets U.S. cryptocurrency and banking services, evades detection through living-off-the-land techniques and sandbox checks, and uses externally hosted payloads and C2 infrastructure for real-time updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.