Researchers reported that Rietspoof operated as a low-prevalence, rapidly evolving multi-stage malware family that began with social-engineering lures delivered through malicious Microsoft Word documents and possibly email or messaging platforms such as Outlook and Skype. The infection chain used an obfuscated VBS script, an embedded CAB archive, signed executables, and later redesigned downloader components, with several stages capable of deleting artifacts, changing the system date, and removing themselves to hinder analysis. Multiple samples carried valid digital signatures, and newer variants added persistence through scheduled tasks, a WindowsUpdate.lnk startup shortcut, and optional service installation.
The malware's command-and-control design changed quickly as operators increased their update cadence from roughly monthly to daily, shifting from raw TCP with negotiated AES-CBC encryption to variants that also used HTTP/HTTPS with hard-coded key material. Its bot stages supported file upload and download, process execution, self-destruction, and payload retrieval, while later stages used NTLM-authenticated TCP channels and, in some cases, fileless execution through cmd and pipes to launch additional malware. Researchers said the infrastructure appeared to geofence responses toward U.S.-based IP addresses, but Rietspoof's final payloads, targeting, and operator objectives remained unclear.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Avast published a blog post analyzing Rietspoof's multi-stage infection chain, persistence, signed payloads, and evolving command-and-control protocols. The report described the malware as low-prevalence and likely acting primarily as a dropper.
Starting on January 22, 2019, newer Rietspoof VBS samples began creating a startup shortcut named "WindowsUpdate.lnk" for persistence. This supplemented or altered the malware's earlier scheduled-task persistence mechanism.
Researchers observed Rietspoof's development accelerate in January 2019, with its update cadence changing from roughly monthly to daily. During this period, Stage 3 communications and obfuscation also changed rapidly.
Researchers began tracking a new multi-stage malware family they named Rietspoof. The family was observed using staged delivery components including malicious documents, scripts, archives, and signed executables.
An update reported on February 20, 2019 stated that Rietspoof was spread using a malicious Microsoft Word document with macros. The document dropped and executed the embedded VBS payload and used social-engineering content to induce macro execution.
A redesigned Rietspoof VBS variant appeared shortly after Avast's February 16, 2019 blog post. Unlike earlier variants, it lacked a digital signature and embedded CAB file, and instead acted directly as a bot/downloader communicating with C2 over HTTP.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
decoded.avast.io
Open sourceblog.avast.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.