Researchers reported an active AVE_MARIA malware campaign delivering the infostealer through phishing lures and multi-stage, stealth-focused execution chains. In one observed intrusion, a malicious VBScript and PowerShell sequence loaded a Revenge RAT reconnaissance component directly into memory from paste.ee, then launched a downloader that performed process hollowing against RegAsm.exe before executing AVE_MARIA. The malware also used a UAC bypass via PkgMgr/DISM DLL hijacking for privilege escalation and communicated with 194.5.98[.]139, infrastructure previously tied to Orcus RAT activity, suggesting overlap with an actor behind earlier Orcus campaigns.
Separate reporting shows the malware family has also been distributed through phishing attachments disguised with an icon resembling AhnLab V3 Lite, alongside AgentTesla payloads. Those samples used a .NET packer to hinder detection, delayed execution with timeout.exe, abused winSAT.exe, escalated privileges with a winmm.dll-based UAC bypass, and likewise injected malicious code into RegAsm.exe. Across the observed campaigns, AVE_MARIA operators have combined social engineering, in-memory staging, privilege escalation, and trusted Windows binaries to evade defenses and steal victim data.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
ASEC released detection names, MD5 hashes, and network indicators associated with the V3 Lite icon masquerade campaign targeting users with AveMaria and AgentTesla malware.
ASEC said the AveMaria samples in the campaign delayed execution with timeout.exe, used winSAT.exe and a winmm.dll-based UAC escalation method, and injected a malicious payload into RegAsm.exe.
ASEC reported an active campaign distributing malware disguised with an icon resembling AhnLab V3 Lite, primarily via phishing email attachments. The campaign delivered AveMaria RAT and AgentTesla and used .NET packing to evade detection.
Morphisec described AVE_MARIA as a relatively new malware family that was first documented toward the end of 2018.
Morphisec reported that the AVE_MARIA sample used a PkgMgr-to-DISM DLL hijacking technique for UAC bypass and communicated with 194.5.98[.]139, an IP previously identified as Orcus RAT infrastructure.
Morphisec Labs reported a phishing campaign delivering AVE_MARIA through a multi-stage, fileless infection chain using a malicious VBScript, in-memory Revenge RAT reconnaissance, and a downloader that hollowed RegAsm.exe before launching the payload.
Morphisec said one downloader component and command-and-control metadata in the AVE_MARIA campaign matched those used in Orcus RAT attacks observed the previous month, leading it to assess the same threat actor was responsible.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.