logo

Trusted Tool Turned Traitor: Signed ‘ahost.exe’ Weaponized to Sideload Malware

ID: fd2e19cd-661f-5dcb-9708-d7c457c2a615

STIX ID: report--fd2e19cd-661f-5dcb-9708-d7c457c2a615

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Trellix observed a global campaign weaponizing DLL sideloading in ahost.exe (a c-ares DNS library component, often distributed with GitKraken) by placing a malicious libcares-2.dll beside a signed executable renamed to appear as business files; executing the signed binary loads the malicious DLL and deploys multiple commodity threats (AgentTesla, FormBook, Lumma, Vidar, CryptBot, Remcos, QuasarRAT, DCRat, XWorm), targeting commercial and industrial sectors and evading traditional AV.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.