A purchase-quotation malspam campaign impersonated an employee of a legitimate company and delivered a recovery-volume-style .r01 RAR attachment containing obfuscated JavaScript tracked as LausivLoader. The script created persistence, stored encrypted payload fragments in a randomly named temporary directory, and passed their locations to a hidden PowerShell process through inherited environment variables. PowerShell reassembled, decoded, AES-decrypted, decompressed, and reflectively loaded a 64-bit .NET component entirely in memory; later stages attempted to impair AMSI protections and retrieved a PNG from yapw[.]life.
The .NET loader was designed to recover a final PE payload from an iTXt metadata chunk within the PNG and execute it in memory or through process hollowing. The final payload was not recovered in the analyzed sample, but the execution chain matches reporting on HypeAgent, a multi-stage infostealer targeting browser credentials, email accounts, cryptocurrency wallets, and authenticated sessions for Claude, ChatGPT, and Cursor, with WebSocket-based command-and-control support. Organizations should block the identified hosting domain, scrutinize quotation-themed archive attachments, and hunt for suspicious hidden PowerShell processes, scheduled-task persistence, and .NET reflective loading activity.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
HypeAgent was documented as a high-severity multi-stage infostealer using JavaScript, PowerShell, .NET loaders, scheduled-task persistence, PNG steganography, reflective loading, AMSI bypass techniques, and process hollowing. It targets browser credentials, email and cryptocurrency accounts, and authenticated Claude, ChatGPT, and Cursor sessions; reported indicators included files.catbox.moe/knujwn.png and 209.54.103.173.
Analysis found that the JavaScript establishes scheduled-task persistence, stages encrypted fragments in a temporary directory, and passes their paths to a hidden PowerShell process through inherited environment variables. The chain decrypts and reflectively loads .NET stages, attempts AMSI interference, and was configured to download a PNG-hosted payload from yapw[.]life, though the final payload was unavailable.
A customer-operated mail gateway quarantined a late-August email impersonating a legitimate-company employee and requesting a quotation for a fiber-optic system. The message failed SPF and DMARC checks and carried an .r01 archive containing an obfuscated JavaScript LausivLoader sample.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
isc.sans.edu
Open sourcemalware.news
Open sourcecommunity.gurucul.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.