Operation DualScript: Multi-Stage PowerShell Malware Targets Crypto
Essential information
- Published
- 31/03/2026 07:10
- Modified
- 31/03/2026 19:19
- Tags
- 2026-03-31 clipboard hijacking cryptocurrency evasion techniques financial theft in-memory execution multi-stage powershell retrorat
- Related entities
- 1 observables, 12 techniques (mitre), 1 malware, 6 others
Description
Operation DualScript is a sophisticated multi-stage malware campaign targeting cryptocurrency and financial activities. It utilizes Windows Scheduled Tasks, VBScript launchers, and PowerShell execution to maintain persistence while minimizing disk artifacts. The attack operates through two parallel chains: a web-based PowerShell loader deploying a cryptocurrency clipboard hijacker, and a secondary chain executing the RetroRAT implant in memory. RetroRAT monitors user activity, captures keystrokes, and tracks interactions with financial services to harvest sensitive information. The malware employs various anti-analysis techniques and establishes a command-and-control channel for remote access and data exfiltration. This campaign highlights the growing abuse of trusted system utilities and in-memory execution techniques to evade traditional detection mechanisms.