How real software downloads can hide remote backdoors
ID: 4d6e947b-a706-50ff-95a3-9cfa472bc276
STIX ID: report--4d6e947b-a706-50ff-95a3-9cfa472bc276
Feed Name: Malwarebytes Blog
This report describes a deceptive campaign that trojanized the RustDesk installer on a fake domain (rustdesk.work) to install legitimate RustDesk alongside a hidden Winos4.0 backdoor. The attack uses a staged loader (logger.exe → Libserver.exe) to unpack large payloads entirely in memory, evade file-based detection, and maintain persistence while communicating with C2 infrastructure (207.56.13.76:5666). IOCs provided include SHA256 hashes for the installer, loader, in-memory modules, the malicious domain, and the C2 IP/port, along with mitigation guidance such as verifying download sources, network monitoring, and application allowlisting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
