Researchers reported a malware campaign using obfuscated VBS and PowerShell stages hosted across multiple DuckDNS domains to infect 64-bit Windows systems with a remote access trojan. The chain decrypts an AES-256-protected PowerShell stage, extracts a 64-bit payload, and uses a .NET helper to hollow AppLaunch.exe for stealthy execution. The malware then establishes persistence through the Windows Startup folder and attempts to weaken defenses by adding Microsoft Defender exclusions.
The RAT communicates with suspected command-and-control infrastructure over port 4577 and is designed for credential theft and surveillance. Reported capabilities include stealing browser credentials and cookies, keylogging, clipboard capture, remote control, and local storage of stolen data, raising the risk of account takeover and broader compromise of enterprise sessions and sensitive information. The reporting includes hashes, filenames, domains, an IP address, and filesystem paths as indicators of compromise, with defenders urged to block the infrastructure, hunt for suspicious PowerShell activity, and isolate affected hosts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Threat researcher Anurag identified a malware campaign that uses obfuscated VBS and AES-256-protected PowerShell stages to deliver a 64-bit Windows remote access trojan via multiple DuckDNS hosts. The observed chain includes process hollowing into AppLaunch.exe, persistence via the Startup folder, Defender exclusion attempts, and C2 communications on port 4577.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.