A multi-actor malware campaign is abusing the legitimate ahost.exe utility to sideload malicious libcares-2.dll files and evade signature-based defenses. Trellix reported that attackers are pairing signed or renamed copies of ahost.exe—a component of the c-ares library commonly bundled with Git for Windows and tools such as GitKraken—with weaponized DLLs to launch a wide range of payloads, including DCRat, XWorm, AgentTesla, FormBook, Lumma Stealer, Vidar, CryptBot, Remcos, and QuasarRAT.
The activity appears broadly distributed worldwide and is using deceptive document-style filenames in multiple languages, including Arabic, Spanish, Portuguese, Farsi, and English, to lure victims. Reported targeting includes employees in finance, procurement, supply chain, and administration across commercial and industrial sectors such as oil and gas and import/export. In one documented DCRat intrusion, attackers renamed ahost.exe to 1DOC-PDF.exe, loaded a malicious DLL, launched AddInProcess32.exe, and maintained persistence by injecting into that process; Trellix urged defenders to prioritize behavioral detection, application control, endpoint hardening, threat intelligence integration, and automated response to counter the sideloading technique.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Trellix observed the campaign using deceptive document-like filenames such as order.exe, RFQ-themed executables, and localized names in Arabic, Spanish, Portuguese, Farsi, and English to induce execution. The filenames indicated a phishing component targeting commercial and industrial organizations including oil and gas and import/export firms.
Trellix stated that GitKraken collaborated with the company and addressed the issue through its bug bounty and service processes after its signed ahost.exe binary was implicated in the sideloading activity. The report highlighted a GitKraken-signed sample associated with multiple malware campaigns.
In one observed case, attackers renamed ahost.exe to 1DOC-PDF.exe and bundled it with a malicious libcares-2.dll carrying DCRat. When executed, the DLL launched AddInProcess32.exe, injected into that process, and persisted under its guise while initiating DNS and C2 activity including contact with dgflex[.]duckdns[.]org.
Trellix reported an active malware campaign in which multiple threat actors abused the legitimate ahost.exe utility by pairing it with a malicious libcares-2.dll to execute payloads. The activity delivered malware including DCRat, XWorm, AgentTesla, FormBook, Lumma Stealer, Vidar, CryptBot, Remcos, and QuasarRAT against business users in roles such as finance, procurement, supply chain, and administration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.