logo

Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

ID: f7730239-f9da-560b-8af3-3c8e0ebceec2

STIX ID: report--f7730239-f9da-560b-8af3-3c8e0ebceec2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

Author: [email protected] (The Hacker News)

...
...

Researchers observed a malspam campaign that abuses Google DoubleClick redirect URLs to funnel victims to dynamically personalized landing pages that deliver a ZIP containing a JavaScript loader; the loader spawns a PowerShell script which fetches a .NET loader that stages and deploys DesckVB RAT. The RAT performs process hollowing into Microsoft-signed processes, disables/patches AMSI and ETW, configures Defender exclusions and persistence, communicates with C2 over raw TCP, and includes data exfiltration and remote control capabilities; defenders are advised to harden email authentication (SPF/DKIM/DMARC), sandbox attachments, and use GPOs to block script execution as a first line of defense.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.