logo

Dissecting New Year-Themed Multi-Stage Malware

ID: 4e4ce180-688a-52d9-a8b7-78791a6e9380

STIX ID: report--4e4ce180-688a-52d9-a8b7-78791a6e9380

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-07-02

Date Updated: 2026-07-16

...
...

CRIL analyzed a New Year-themed spam campaign where a ZIP attachment contains a PNG file that is actually a LNK shortcut; when executed it launches an HTA via mshta which displays a benign-looking greeting image while downloading and decoding a malicious payload. The payload chain drops and merges binaries into a malicious nView.dll and a legitimate nvTaskBar.exe, achieves persistence via a scheduled task, employs DLL sideloading to execute further DLLs (including NVDriverSearch.ct), and communicates with a C2 (91.245.253.46:443) consistent with a Remcos RAT; the report provides hashes, URLs, and MITRE ATT&CK mappings as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.