Threat researchers reported multiple active campaigns focused on stealthy malware delivery by abusing trusted execution paths and deceptive distribution. Trellix described attackers using DLL side-loading against a legitimate, signed ahost.exe binary associated with the c-ares ecosystem (commonly seen with GitKraken Desktop) by placing a malicious libcares-2.dll alongside the executable to trigger search-order hijacking and execute attacker code. The activity was linked to delivery of commodity malware families including Agent Tesla, Formbook, Remcos RAT, Quasar RAT, DCRat, XWorm, Vidar Stealer, Lumma Stealer, CryptBot, and others, with targeting observed across business functions (finance, procurement, supply chain, administration) and lures in multiple languages, suggesting regionally focused operations.
Separately, Malwarebytes documented a fake RustDesk download site (rustdesk[.]work) that installs legitimate RustDesk while silently deploying a persistent backdoor framework (Winos4.0) via a trojanized installer (e.g., rustdesk-1.4.4-x86_64.exe), relying on user deception rather than exploiting a software vulnerability. Sucuri detailed a WordPress compromise where attackers modified index.php to perform selective content injection/SEO cloaking, using IP-verified logic with hardcoded Google ASN CIDR ranges to serve malicious content to Googlebot while showing normal content to human visitors and site owners—an evasion technique that can facilitate downstream malware distribution while reducing the chance of detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Further reporting said the DLL side-loading activity primarily targeted employees in oil and gas and import/export organizations, with lures aimed at business functions such as finance and procurement. Observed payloads included Agent Tesla, XWorm, DCRat, Remcos RAT, Vidar Stealer, Lumma Stealer, Formbook, and CryptBot.
Trend Micro reported a separate phishing chain, previously documented by Forcepoint X-Labs, that used Dropbox-delivered ZIP archives and TryCloudflare tunnels or WebDAV to stage scripts, install a Python environment, persist via the startup folder, and inject AsyncRAT into explorer.exe while displaying a decoy PDF. This added new technical detail on an ongoing multi-stage malware delivery method.
Trellix also disclosed a surge in Facebook credential-phishing campaigns using the Browser-in-the-Browser technique, often beginning with phishing emails and leading victims to fake Meta CAPTCHA pages and counterfeit login pop-ups hosted on platforms such as Netlify or Vercel. The activity highlighted broader abuse of trusted web services in phishing operations.
Trellix reported an active campaign abusing DLL side-loading through a legitimate signed GitKraken binary, ahost.exe, by placing a malicious libcares-2.dll beside it to hijack DLL loading. The technique was used to evade defenses and deliver multiple commodity trojans and stealers.
Researchers detailed the RustDesk-themed infection chain, including in-memory staging via logger.exe and Libserver.exe, anti-analysis behavior, encrypted registry-stored configuration, and command-and-control traffic to 207.56.13[.]76 over TCP port 5666. The report also published file hashes and network indicators of compromise for detection and response.
A malware campaign used the typosquatted domain rustdesk[.]work to impersonate the legitimate RustDesk project and trick users into downloading a trojanized installer. The installer delivered a real, functional RustDesk client while covertly deploying the Winos4.0 (WinosStager) backdoor for persistent remote access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.