From Malspam to Fileless .NET Loader
June 10, 2026, 8:30 a.m.
Description
A sophisticated malspam campaign delivers a multi-stage .NET loader through an elaborate chain beginning with HTML email attachments. The attack routes through legitimate Google DoubleClick infrastructure to evade detection, then deploys a dynamically personalized phishing kit that pulls victim company branding in real-time. The infection chain progresses through JavaScript, PowerShell, and multiple .NET components, executing primarily in-memory while actively patching AMSI and ETW to blind Windows telemetry. The loader performs extensive anti-analysis checks, terminates or reboots upon detecting sandboxes or debugging tools, and establishes persistence through registry keys and scheduled tasks disguised as NVIDIA components. It targets Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe for process injection, maintains C2 communications over non-standard ports using AES-encrypted protobuf messages, and profiles victim systems including specific GPU enumeration potentially for cryptocurrency min...
Tags
Date
- Created: June 9, 2026, 3:50 p.m.
- Published: June 9, 2026, 3:50 p.m.
- Modified: June 10, 2026, 8:30 a.m.
Indicators
- c356aff1a01c2b0da472e584c8e3c8f875b9a24280435d42836a77b19f5a8c18
- d5b7247c497788cf0031ceb06e3df77a45fef59f1e49633dc7159816d64759b5
- e91fb249aa97be5c7931e430781167edfe7ba804720b5f643e6ab70b7e6e74dd
- f1c3ebe78bd8c38559bf3cfcc9a9fa37d221e31780774a3787e26160a61f5348
- c61b1941cf756eb7551f7c661743802362728b785adc22e860d269713dfb01a6
- http://catalogo.castrouria.com/c84da/bl.txt
- https://andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br/GpazlLUWIJ_14_05_Meus_ArquivosDeTexto/02.txt
- https://pengajian.muliastudy.com/images/edu/u.php
- http://pengajian.muliastudy.com/images/edu/u.php
Additional Informations
- bth.startthewave.org
- xtadts.ddns.net
- catalogo.castrouria.com
- andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br
- pengajian.muliastudy.com
- afxwd.ddns.net
- fostercareintheus.optimizationprime.com