Researchers disclosed Operation PhantomCLR, a malware campaign that abuses Microsoft .NET's AppDomainManager mechanism to hijack execution of the legitimate, digitally signed Intel utility IAStorHelp.exe without altering the original binary. The intrusion chain begins with spear-phishing emails carrying a disguised .pdf.lnk file; when opened, it launches the Intel binary, loads a malicious configuration and DLL, and presents a decoy Saudi ministry-themed document to the victim. Reported targeting has focused on organizations in the Middle East and the broader EMEA financial sector.
CYFIRMA said the framework functions as a multi-stage post-exploitation platform comparable to Cobalt Strike and Brute Ratel C4, with anti-analysis, in-memory execution, and anti-forensic features. The malware reportedly delays execution through CPU-intensive calculations and an AES key-derivation loop to evade sandboxes, then uses a JIT trampoline to run shellcode in memory and a DLL injection storm to mask activity. Command-and-control traffic is routed through Amazon CloudFront using domain fronting so communications blend with legitimate cloud traffic; defenders were urged to treat affected hosts as fully compromised, block identified C2 infrastructure, inspect CDN-bound TLS traffic, and harden .NET AppDomainManager usage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
CYFIRMA published research on Operation PhantomCLR, describing a malware campaign that abuses Microsoft .NET AppDomainManager to hijack execution of the legitimate signed Intel utility IAStorHelp.exe without modifying the binary. The report said the campaign targeted organizations in the Middle East and EMEA financial sectors and used spear-phishing with disguised .pdf.lnk files, decoy documents, in-memory execution, and CloudFront-based domain fronting for C2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyfirma.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.