The primary attack vector observed involves email phishing campaigns carrying deceptive lures regarding product damages or refund processing. These communications lure recipients to external web pages that impersonate cloud document-sharing services or video preview interfaces. To circumvent file size restrictions on preview pages, the platforms prompt targets to download compressed archive files containing dual-extension executables alongside dynamic link libraries. The malicious operational scope targets corporate desktop infrastructure, primarily endpoint systems processing consumer communications and operational inquiries. The business impact stems from unauthorized endpoint access, system credential compromise, and sensitive data harvesting, which compromises organizational data integrity and exposes internal communications to unauthorized remote access. Furthermore, the operational delivery infrastructure relies on automated mail distribution libraries and external file-sharing application programming interfaces to maintain high-volume outreach across regional target environments. The threat payload delivery mechanism utilizes diverse execution loaders designed to drop administrative remote access trojans or credential stealers onto vulnerable host environments. Endpoint vulnerability arises from compromised user execution of double-extension binaries masking as benign documentation files. The infection lifecycle transitions seamlessly from initial lure interaction to full endpoint takeover without requiring traditional software exploit chains. Consequently, affected organizations risk sensitive document exfiltration, browser credential extraction, messaging communication monitoring, and underlying host manipulation, severe operational disruptions, and secondary compromise vectors within infected enterprise networks.
Execution begins when a user runs an executable using double extensions to masquerade as document files, triggering secondary library loading. The primary loader component displays a decoy document to deceive the target while extracting secondary archives into public directory structures or establishing execution persistence. Persistence mechanisms incorporate system startup folder shortcut creation, scheduled task registration, and registry run key insertions. Specialized loaders employ custom shellcode reconstruction, pulling fragmented byte sequences from binary resources to reconstruct in-memory execution payloads based on specialized shellcode generators. Execution flows incorporate advanced evasion techniques, including Antimalware Scan Interface and Event Tracing for Windows suppression, combined with anti-debugging and anti-sandbox validations. Certain loader variants bundle script execution environments, utilizing obfuscated scripts to decrypt and execute secondary loaders or downloaders directly in system memory. Advanced variants perform process hollowing to inject code into legitimate processes or deploy signed vulnerable kernel drivers to execute bring-your-own-vulnerable-driver attacks. The driver component uses targeted input-output control codes to issue system process termination requests against active security product process identifiers with elevated privileges. Network behavior includes outbound requests using custom symmetric and asymmetric encryption protocols, symmetric payload compression, and web sockets to download secondary plugins, stream host metrics, exfiltrate browser credentials, capture system display frames, and transmit messaging application data to remote command servers.[/subscribe_to_unlock_form]
The primary attack vector observed involves email phishing campaigns carrying deceptive lures regarding product damages or refund processing. These communications lure recipients to external web pages that impersonate cloud document-sharing services or video preview interfaces. To circumvent file size restrictions on preview pages, the platforms prompt targets to download compressed archive files containing dual-extension executables alongside dynamic link libraries. The malicious operational scope targets corporate desktop infrastructure, primarily endpoint systems processing consumer communications and operational inquiries. The business impact stems from unauthorized endpoint access, system credential compromise, and sensitive data harvesting, which compromises organizational data integrity and exposes internal communications to unauthorized remote access. Furthermore, the operational delivery infrastructure relies on automated mail distribution libraries and external file-sharing application programming interfaces to maintain high-volume outreach across regional target environments. The threat payload delivery mechanism utilizes diverse execution loaders designed to drop administrative remote access trojans or credential stealers onto vulnerable host environments. Endpoint vulnerability arises from compromised user execution of double-extension binaries masking as benign documentation files. The infection lifecycle transitions seamlessly from initial lure interaction to full endpoint takeover without requiring traditional software exploit chains. Consequently, affected organizations risk sensitive document exfiltration, browser credential extraction, messaging communication monitoring, and underlying host manipulation, severe operational disruptions, and secondary compromise vectors within infected enterprise networks.
Execution begins when a user runs an executable using double extensions to masquerade as document files, triggering secondary library loading. The primary loader component displays a decoy document to deceive the target while extracting secondary archives into public directory structures or establishing execution persistence. Persistence mechanisms incorporate system startup folder shortcut creation, scheduled task registration, and registry run key insertions. Specialized loaders employ custom shellcode reconstruction, pulling fragmented byte sequences from binary resources to reconstruct in-memory execution payloads based on specialized shellcode generators. Execution flows incorporate advanced evasion techniques, including Antimalware Scan Interface and Event Tracing for Windows suppression, combined with anti-debugging and anti-sandbox validations. Certain loader variants bundle script execution environments, utilizing obfuscated scripts to decrypt and execute secondary loaders or downloaders directly in system memory. Advanced variants perform process hollowing to inject code into legitimate processes or deploy signed vulnerable kernel drivers to execute bring-your-own-vulnerable-driver attacks. The driver component uses targeted input-output control codes to issue system process termination requests against active security product process identifiers with elevated privileges. Network behavior includes outbound requests using custom symmetric and asymmetric encryption protocols, symmetric payload compression, and web sockets to download secondary plugins, stream host metrics, exfiltrate browser credentials, capture system display frames, and transmit messaging application data to remote command servers.[emaillocker id="1283"]
The campaign underscores a persistent security risk characterized by modular loader designs delivering standardized remote access and credential theft capabilities. By continuously altering execution loaders while keeping core payloads consistent, the threat effectively evades signature-based detection mechanisms and endpoint defenses relying on static file indicators. The integration of advanced defense evasion techniques, such as bypasses for security event tracing, script environment bundling, process hollowing, and driver-based process termination, highlights a sophisticated technical strategy aimed at neutralizing security software prior to full payload execution. This threat reflects a broader trend in the threat landscape where adversaries prioritize initial execution evasion and endpoint security driver manipulation over developing unique payload functionality. The operational reliance on legitimate cloud services, public file-hosting APIs, and automated mailing tools complicates network-level detection and perimeter filtering efforts. Organizations face heightened risks from modular, multi-stage delivery chains that blend social engineering with kernel-level driver abuse to achieve silent host compromise. Understanding these execution flows and loader mechanics is critical for developing behavior-based detection models capable of identifying host evasion, process manipulation, and driver-based privilege abuse across host environments.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Defence Evasion | T1070.004 | Indicator Removal | File Deletion |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
The following reports contain further technical details:
[/emaillocker]