Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT

June 4, 2026, 9:08 a.m.

Description

DesckVB RAT emerged in February 2026 through a sophisticated malspam campaign utilizing a dynamic delivery kit that personalizes lures on-the-fly by extracting victim email addresses and pulling company logos in real-time. The attack chain routes through Google's DoubleClick domain to evade email gateways before delivering a five-stage infection: HTML redirect, JScript loader, PowerShell dropper, .NET loader, and finally the RAT itself. The malware employs extensive anti-analysis techniques including sandbox detection, forced reboots upon detection, and in-memory execution via .NET reflection. Once established, it patches AMSI and ETW at the native API level, injects into legitimate Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe, and establishes persistence through registry keys and scheduled tasks. The RAT communicates with DDNS-based C2 infrastructure on non-standard ports, performs system reconnaissance including GPU enumeration possibly for crypto mining, and can deliver additional payl...

Date

  • Created: June 3, 2026, 1:18 p.m.
  • Published: June 3, 2026, 1:18 p.m.
  • Modified: June 4, 2026, 9:08 a.m.

Indicators

  • c356aff1a01c2b0da472e584c8e3c8f875b9a24280435d42836a77b19f5a8c18
  • d5b7247c497788cf0031ceb06e3df77a45fef59f1e49633dc7159816d64759b5
  • e91fb249aa97be5c7931e430781167edfe7ba804720b5f643e6ab70b7e6e74dd
  • f1c3ebe78bd8c38559bf3cfcc9a9fa37d221e31780774a3787e26160a61f5348
  • c61b1941cf756eb7551f7c661743802362728b785adc22e860d269713dfb01a6
  • https://andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br/GpazlLUWIJ_14_05_Meus_ArquivosDeTexto/02.txt
  • https://pengajian.muliastudy.com/images/edu/u.php
  • http://pengajian.muliastudy.com/images/edu/u.php

Additional Informations

  • bth.startthewave.org
  • xtadts.ddns.net
  • catalogo.castrouria.com
  • andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br
  • pengajian.muliastudy.com
  • afxwd.ddns.net
  • fostercareintheus.optimizationprime.com