Dissecting New Year-Themed Multi-Stage Malware
ID: 4e4ce180-688a-52d9-a8b7-78791a6e9380
STIX ID: report--4e4ce180-688a-52d9-a8b7-78791a6e9380
Feed Name: Cyble Blog
CRIL analyzed a New Year-themed spam campaign where a ZIP attachment contains a PNG file that is actually a LNK shortcut; when executed it launches an HTA via mshta which displays a benign-looking greeting image while downloading and decoding a malicious payload. The payload chain drops and merges binaries into a malicious nView.dll and a legitimate nvTaskBar.exe, achieves persistence via a scheduled task, employs DLL sideloading to execute further DLLs (including NVDriverSearch.ct), and communicates with a C2 (91.245.253.46:443) consistent with a Remcos RAT; the report provides hashes, URLs, and MITRE ATT&CK mappings as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
