Operation DualScript Bypasses Defenses to Hijack Crypto and Cash
ID: cfa3eccf-9b73-52c0-8c1a-7c109c7b9313
STIX ID: report--cfa3eccf-9b73-52c0-8c1a-7c109c7b9313
Feed Name: securityonline.info
Operation DualScript is a sophisticated, multi-stage in-memory malware campaign that establishes persistence via Windows Scheduled Tasks to run two parallel chains: a PowerShell-based clipboard hijacker that replaces copied cryptocurrency addresses and a RetroRAT implant providing keystroke capture and remote control; the campaign targets U.S. cryptocurrency and banking services, evades detection through living-off-the-land techniques and sandbox checks, and uses externally hosted payloads and C2 infrastructure for real-time updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
