Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
June 4, 2026, 9:08 a.m.
Description
DesckVB RAT emerged in February 2026 through a sophisticated malspam campaign utilizing a dynamic delivery kit that personalizes lures on-the-fly by extracting victim email addresses and pulling company logos in real-time. The attack chain routes through Google's DoubleClick domain to evade email gateways before delivering a five-stage infection: HTML redirect, JScript loader, PowerShell dropper, .NET loader, and finally the RAT itself. The malware employs extensive anti-analysis techniques including sandbox detection, forced reboots upon detection, and in-memory execution via .NET reflection. Once established, it patches AMSI and ETW at the native API level, injects into legitimate Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe, and establishes persistence through registry keys and scheduled tasks. The RAT communicates with DDNS-based C2 infrastructure on non-standard ports, performs system reconnaissance including GPU enumeration possibly for crypto mining, and can deliver additional payl...
Tags
Date
- Created: June 3, 2026, 1:18 p.m.
- Published: June 3, 2026, 1:18 p.m.
- Modified: June 4, 2026, 9:08 a.m.
Indicators
- c356aff1a01c2b0da472e584c8e3c8f875b9a24280435d42836a77b19f5a8c18
- d5b7247c497788cf0031ceb06e3df77a45fef59f1e49633dc7159816d64759b5
- e91fb249aa97be5c7931e430781167edfe7ba804720b5f643e6ab70b7e6e74dd
- f1c3ebe78bd8c38559bf3cfcc9a9fa37d221e31780774a3787e26160a61f5348
- c61b1941cf756eb7551f7c661743802362728b785adc22e860d269713dfb01a6
- https://andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br/GpazlLUWIJ_14_05_Meus_ArquivosDeTexto/02.txt
- https://pengajian.muliastudy.com/images/edu/u.php
- http://pengajian.muliastudy.com/images/edu/u.php
Additional Informations
- bth.startthewave.org
- xtadts.ddns.net
- catalogo.castrouria.com
- andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br
- pengajian.muliastudy.com
- afxwd.ddns.net
- fostercareintheus.optimizationprime.com