Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantloader-delivery-mechanismdefense-evasion-methodphishing-campaign-intelligence

Multi-stage malware campaigns using fileless loaders, RATs, and evasion techniques

Updated 3mo agoFirst seen Mar 12, 20264 sources

Multiple reports detail distinct, unrelated malware families and delivery chains rather than a single shared incident. One analysis covers NotOpenClaw, a Windows malware loader distributed via fake “OpenClaw” installers (including GitHub-hosted lures) and emphasizing VM/sandbox evasion; the sample analyzed was tagged with stealer-related indicators (e.g., VidarStealer) and was previously referenced in third-party reporting about fake OpenClaw installers deploying additional malware.

Separate research describes two different fileless/backdoor operations: HellsUchecker, a small native x64 backdoor delivered through a 10-stage chain beginning with a ClickFix fake Cloudflare CAPTCHA that tricks users into pasting an obfuscated Run command, using a LOLBin to fetch payloads over finger (TCP/79) and retrieving encrypted C2 configuration from a BNB Smart Chain smart contract ("EtherHiding"), culminating in an in-memory final payload using Hell’s Gate direct syscalls; and GhostWeaver, a fileless PowerShell RAT that selects persistence based on the installed AV product, uses TLS over TCP/25658, and relies on multiple DGA routines for delivery and C2. A separate brief reports the VOID#GEIST campaign delivering XWorm, AsyncRAT, and Xeno RAT via phishing, batch scripts from TryCloudflare domains, staged ZIP payloads, Python-based decryption/execution, and abuse of AppInstallerPythonRedirector.exe to facilitate additional RAT deployment.

Share:
Multi-stage malware campaigns using fileless loaders, RATs, and evasion techniques
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 11, 20263mo ago

Analyst identifies NotOpenClaw fake AI installer malware

An analysis of a Windows sample posing as an OpenClaw AI installer identified a Rust-based loader dubbed NotOpenClaw, featuring extensive VM and sandbox evasion plus a staged PowerShell script that weakens Windows Defender and firewall protections. After patching anti-analysis checks, the analyst observed network activity, extracted limited IOCs, and linked the sample to prior fake OpenClaw installer activity.

Researchers observe active HellsUchecker ClickFix campaign

A 10-stage malware campaign using a fake Cloudflare Turnstile ClickFix lure was reported active, chaining finger.exe, Python bootstrapping, an MSI dropper, an EtherHiding loader, and the in-memory HellsUchecker backdoor. The operation used blockchain-hosted C2 configuration, anti-analysis checks, persistence via a BAT/MSBuild polyglot and Startup link, and direct-syscall injection.

Mar 10, 20263mo ago

Researchers publish GhostWeaver PowerShell RAT analysis

Researchers analyzed GhostWeaver, a fileless in-memory PowerShell RAT with antivirus-aware persistence, DGA-based C2, and sandbox evasion through the MintsLoader profiler. They also connected to two live C2 servers and observed both immediately deliver identical persistence payloads, and attributed the activity to TA582/UNC4108 linked downstream of the SocGholish infection chain.

Researchers document VOID#GEIST multi-RAT malware campaign

Researchers disclosed a modular malware campaign dubbed VOID#GEIST that begins with phishing emails and weaponized batch scripts hosted on TryCloudflare domains. The intrusion chain delivers XWorm, Xeno RAT, and AsyncRAT in stages, using PowerShell persistence, Python-based decryption, and process injection to improve flexibility and resilience.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

42 LINKEDOpen in app
Threat actors
1 linked
Affected products
8 linked
WindowsNetApache Http ServerVisual StudioOpensshPythonUbuntuVirustotal
Organizations
24 linked
CloudflarePython Software FoundationMicrosoft CorporationHostingerChangeNOWVDSINABeget LLCGlobal Domain Group LLCLimited Network LTDSERVERS TECH FZCOOmegatech LTDTRAC LabsSecuronixVirustotalRecorded FutureAvastGitHubHuntressWebrootOpenDNSHurricane ElectricGoogleThe Hacker NewsControl D
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.