Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismdefense-evasion-methodsearch-ad-manipulationremote-access-implant

Malware Delivery via Deceptive Distribution and Evasion Techniques

Updated 3mo agoFirst seen Jan 14, 20263 sources

Threat researchers reported multiple active campaigns focused on stealthy malware delivery by abusing trusted execution paths and deceptive distribution. Trellix described attackers using DLL side-loading against a legitimate, signed ahost.exe binary associated with the c-ares ecosystem (commonly seen with GitKraken Desktop) by placing a malicious libcares-2.dll alongside the executable to trigger search-order hijacking and execute attacker code. The activity was linked to delivery of commodity malware families including Agent Tesla, Formbook, Remcos RAT, Quasar RAT, DCRat, XWorm, Vidar Stealer, Lumma Stealer, CryptBot, and others, with targeting observed across business functions (finance, procurement, supply chain, administration) and lures in multiple languages, suggesting regionally focused operations.

Separately, Malwarebytes documented a fake RustDesk download site (rustdesk[.]work) that installs legitimate RustDesk while silently deploying a persistent backdoor framework (Winos4.0) via a trojanized installer (e.g., rustdesk-1.4.4-x86_64.exe), relying on user deception rather than exploiting a software vulnerability. Sucuri detailed a WordPress compromise where attackers modified index.php to perform selective content injection/SEO cloaking, using IP-verified logic with hardcoded Google ASN CIDR ranges to serve malicious content to Googlebot while showing normal content to human visitors and site owners—an evasion technique that can facilitate downstream malware distribution while reducing the chance of detection.

Share:
Malware Delivery via Deceptive Distribution and Evasion Techniques
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 15, 20265mo ago

Sector targeting and payload details emerge in DLL side-loading campaign

Further reporting said the DLL side-loading activity primarily targeted employees in oil and gas and import/export organizations, with lures aimed at business functions such as finance and procurement. Observed payloads included Agent Tesla, XWorm, DCRat, Remcos RAT, Vidar Stealer, Lumma Stealer, Formbook, and CryptBot.

Jan 14, 20265mo ago

Trend Micro describes multi-stage AsyncRAT phishing chain

Trend Micro reported a separate phishing chain, previously documented by Forcepoint X-Labs, that used Dropbox-delivered ZIP archives and TryCloudflare tunnels or WebDAV to stage scripts, install a Python environment, persist via the startup folder, and inject AsyncRAT into explorer.exe while displaying a decoy PDF. This added new technical detail on an ongoing multi-stage malware delivery method.

Trellix reports rise in Facebook BitB credential-phishing

Trellix also disclosed a surge in Facebook credential-phishing campaigns using the Browser-in-the-Browser technique, often beginning with phishing emails and leading victims to fake Meta CAPTCHA pages and counterfeit login pop-ups hosted on platforms such as Netlify or Vercel. The activity highlighted broader abuse of trusted web services in phishing operations.

Trellix discloses c-ares DLL side-loading malware campaign

Trellix reported an active campaign abusing DLL side-loading through a legitimate signed GitKraken binary, ahost.exe, by placing a malicious libcares-2.dll beside it to hijack DLL loading. The technique was used to evade defenses and deliver multiple commodity trojans and stealers.

Winos4.0 backdoor activity and IOCs are documented

Researchers detailed the RustDesk-themed infection chain, including in-memory staging via logger.exe and Libserver.exe, anti-analysis behavior, encrypted registry-stored configuration, and command-and-control traffic to 207.56.13[.]76 over TCP port 5666. The report also published file hashes and network indicators of compromise for detection and response.

Typosquatted RustDesk site distributes trojanized installer

A malware campaign used the typosquatted domain rustdesk[.]work to impersonate the legitimate RustDesk project and trick users into downloading a trojanized installer. The installer delivered a real, functional RustDesk client while covertly deploying the Winos4.0 (WinosStager) backdoor for persistent remote access.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

32 LINKEDOpen in app
Affected products
8 linked
WindowsRustdeskFacebookVercelPowershellWindows Script HostDropboxDropbox
Organizations
13 linked
GitkrakenTrellixThe Hacker NewsTrend MicroRustdeskMalwarebytesForcepointCloudflareDropboxMeta PlatformsVercelNetlifyGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Malware Delivery via Deceptive Distribution and Evasion Techniques | Mallory