From Malspam to Fileless .NET Loader

June 10, 2026, 8:30 a.m.

Description

A sophisticated malspam campaign delivers a multi-stage .NET loader through an elaborate chain beginning with HTML email attachments. The attack routes through legitimate Google DoubleClick infrastructure to evade detection, then deploys a dynamically personalized phishing kit that pulls victim company branding in real-time. The infection chain progresses through JavaScript, PowerShell, and multiple .NET components, executing primarily in-memory while actively patching AMSI and ETW to blind Windows telemetry. The loader performs extensive anti-analysis checks, terminates or reboots upon detecting sandboxes or debugging tools, and establishes persistence through registry keys and scheduled tasks disguised as NVIDIA components. It targets Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe for process injection, maintains C2 communications over non-standard ports using AES-encrypted protobuf messages, and profiles victim systems including specific GPU enumeration potentially for cryptocurrency min...

Date

  • Created: June 9, 2026, 3:50 p.m.
  • Published: June 9, 2026, 3:50 p.m.
  • Modified: June 10, 2026, 8:30 a.m.

Indicators

  • c356aff1a01c2b0da472e584c8e3c8f875b9a24280435d42836a77b19f5a8c18
  • d5b7247c497788cf0031ceb06e3df77a45fef59f1e49633dc7159816d64759b5
  • e91fb249aa97be5c7931e430781167edfe7ba804720b5f643e6ab70b7e6e74dd
  • f1c3ebe78bd8c38559bf3cfcc9a9fa37d221e31780774a3787e26160a61f5348
  • c61b1941cf756eb7551f7c661743802362728b785adc22e860d269713dfb01a6
  • http://catalogo.castrouria.com/c84da/bl.txt
  • https://andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br/GpazlLUWIJ_14_05_Meus_ArquivosDeTexto/02.txt
  • https://pengajian.muliastudy.com/images/edu/u.php
  • http://pengajian.muliastudy.com/images/edu/u.php

Additional Informations

  • bth.startthewave.org
  • xtadts.ddns.net
  • catalogo.castrouria.com
  • andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br
  • pengajian.muliastudy.com
  • afxwd.ddns.net
  • fostercareintheus.optimizationprime.com

Linked vulnerabilities