Splunk Unmasks New Malware Campaign Pairing Ghost RAT with CloverPlus Adware
ID: eba43482-a942-5be5-b5a5-47c4ee60276f
STIX ID: report--eba43482-a942-5be5-b5a5-47c4ee60276f
Feed Name: securityonline.info
Threat Score
The Splunk Threat Research Team describes a dual-purpose malware campaign that uses an obfuscated loader to deploy Ghost RAT (a persistent backdoor with privilege escalation, VM checks, hosts/DNS manipulation, and RDP keylogging to capture credentials) alongside CloverPlus adware to monetize victims, detailing execution via rundll32, registry persistence, and other defense-evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
