logo

Splunk Unmasks New Malware Campaign Pairing Ghost RAT with CloverPlus Adware

ID: eba43482-a942-5be5-b5a5-47c4ee60276f

STIX ID: report--eba43482-a942-5be5-b5a5-47c4ee60276f

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

The Splunk Threat Research Team describes a dual-purpose malware campaign that uses an obfuscated loader to deploy Ghost RAT (a persistent backdoor with privilege escalation, VM checks, hosts/DNS manipulation, and RDP keylogging to capture credentials) alongside CloverPlus adware to monetize victims, detailing execution via rundll32, registry persistence, and other defense-evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.