Huntress researchers reported a malspam campaign that abuses Google’s DoubleClick domain to make phishing traffic appear legitimate and deliver the DesckVB RAT. The attack begins with a phishing email containing an HTML attachment that uses a meta-refresh redirect through a DoubleClick tracking URL and other redirectors before sending victims to a personalized landing page. That page incorporates the target’s email address, company branding, and location details, then prompts them to click a fake “Download PDF” button that retrieves a ZIP archive.
Opening the archive triggers a JavaScript-based infection chain that leads to PowerShell activity and a .NET loader, which performs anti-analysis checks, weakens security controls, establishes persistence, and injects the RAT into legitimate Microsoft-signed processes using process hollowing. Once installed, DesckVB communicates over command-and-control channels, patches AMSI and ETW, adds Microsoft Defender exclusions, conducts reconnaissance, steals data, executes commands, and can deploy additional payloads. Researchers said organizations should harden email defenses with DMARC, DKIM, and SPF, use sandboxing-capable email gateways, and consider Group Policy changes that force risky script file types to open in Notepad.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
SC Media reports that the DesckVB RAT has been active since February 2026. The malware supports persistence, defense evasion, command execution, data theft, and delivery of additional payloads.
Huntress researchers identified a malspam campaign that abuses Google DoubleClick redirect URLs to make phishing traffic appear more legitimate and deliver the DesckVB RAT. The infection chain uses an HTML attachment, redirectors, a personalized fake document page, and a ZIP/JavaScript/.NET loader sequence ending in process hollowing into Microsoft-signed processes.
On June 3, 2026, Huntress published analysis of the malspam campaign and said its earlier attribution to DesckVB RAT was incorrect. The firm assessed the intrusion chain as delivering an unidentified in-memory .NET loader with anti-analysis, persistence, Defender tampering, and additional payload delivery capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.