216.73.216.6

Not Just Annoying Ads: Adware Bundles Delivering Gh0st RAT

· Published 17/04/2026 23:18 · Modified 20/04/2026 10:52

Export JSON

Essential information

Published
17/04/2026 23:18
Modified
20/04/2026 10:52
Tags
2026-04-17 adware bundle cloverplus dead drop resolver dns hijacking gh0st rat keylogging registry persistence remote access trojan
Related entities
1 vulnerabilities (cve), 2 observables, 19 techniques (mitre), 3 malware

Description

A sophisticated malware campaign is distributing both Gh0st and adware simultaneously through obfuscated loaders. The loader drops encrypted payloads from its resource section, with one being adware and another a DLL module executed via rundll32.exe. The RAT employs multiple persistence mechanisms including registry run keys, Windows services, and Remote Access service manipulation. It features capabilities for token manipulation, , targeting RDP sessions, system reconnaissance, and techniques for C2 communication. The malware specifically targets security tools by blocking antivirus domains through DNS spoofing and hosts file modification. This dual-payload approach provides attackers with long-term system access while generating immediate profit through adware monetization.

External references