216.73.216.233

Operation DualScript: Multi-Stage PowerShell Malware Targets Crypto

· Published 31/03/2026 07:10 · Modified 31/03/2026 19:19

Export JSON

Essential information

Published
31/03/2026 07:10
Modified
31/03/2026 19:19
Tags
2026-03-31 clipboard hijacking cryptocurrency evasion techniques financial theft in-memory execution multi-stage powershell retrorat
Related entities
1 observables, 12 techniques (mitre), 1 malware, 6 others

Description

Operation DualScript is a sophisticated malware campaign targeting and financial activities. It utilizes Windows Scheduled Tasks, VBScript launchers, and execution to maintain persistence while minimizing disk artifacts. The attack operates through two parallel chains: a web-based loader deploying a clipboard hijacker, and a secondary chain executing the implant in memory. monitors user activity, captures keystrokes, and tracks interactions with financial services to harvest sensitive information. The malware employs various anti-analysis techniques and establishes a command-and-control channel for remote access and data exfiltration. This campaign highlights the growing abuse of trusted system utilities and techniques to evade traditional detection mechanisms.

External references