Trusted Tool Turned Traitor: Signed ‘ahost.exe’ Weaponized to Sideload Malware
ID: fd2e19cd-661f-5dcb-9708-d7c457c2a615
STIX ID: report--fd2e19cd-661f-5dcb-9708-d7c457c2a615
Feed Name: securityonline.info
Trellix observed a global campaign weaponizing DLL sideloading in ahost.exe (a c-ares DNS library component, often distributed with GitKraken) by placing a malicious libcares-2.dll beside a signed executable renamed to appear as business files; executing the signed binary loads the malicious DLL and deploys multiple commodity threats (AgentTesla, FormBook, Lumma, Vidar, CryptBot, Remcos, QuasarRAT, DCRat, XWorm), targeting commercial and industrial sectors and evading traditional AV.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
