InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Mintsloader drops GhostWeaver via phishing, Clickfix – using DGA, TLS for stealth attacks
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Mintsloader drops GhostWeaver via phishing, Clickfix – using DGA, TLS for stealth attacks
Technology

Mintsloader drops GhostWeaver via phishing, Clickfix – using DGA, TLS for stealth attacks

May 2, 2025 3 Min Read
Share
MintsLoader Drops GhostWeaver via Phishing, ClickFix
SHARE

Malware loader known as Mintsloader PowerShell-based Remote Access is used to provide a Trojan called a Trojan.

“Mintsloader works through a multi-stage infection chain containing obfuscated JavaScript and Powershell scripts,” the Insikt group at Future said in a report shared with Hacker News.

“Malware employs sandbox and virtual machine avoidance technologies for domain generation algorithms (DGAs) and HTTP-based command-and-control (C2) communication.”

Distributed phishing and drive-by download campaigns have been detected wild since early 2023 for each orange cyber defense. Loaders have been observed to provide modified versions such as various subsequent payloads such as STEALC and Berkeley Open Infrastructure (BOINC) clients for network computing.

Malware is also used by threat actors who run e-Crime services such as Socgholish (aka FakeUpdates) and Landupdate808 (aka TAG-124) and is distributed via phishing emails targeting the industry, legal and energy sectors, as well as fake browser update prompts.

Mintsloader drops GhostWeaver via phishing, Clickfix

With a notable twist, recent attack waves employ an increasingly popular social engineering tactic called Clickfix to trick site visitors and copy and run malicious JavaScript and PowerShell code. Links to Clickfix pages will be distributed via spam email.

“Mintsloader only functions as a loader without supplemental features, but its main strength lies in its sandbox and virtual machine avoidance technology, as well as its DGA implementation that derives the C2 domain based on the date it was run,” said Future, recorded.

Use DGA and TLS for stealth attacks

These features, coupled with obfuscation techniques, can prevent threat actors from analyzing and complicate detection efforts. The main responsibility of the malware is to use PowerShell scripts to download the next stage payload from the DGA domain via HTTP.

See also  Malware attacks target global uyghur parliament leaders via troilized uyghuredit++ tools

GhostWeaver is designed to maintain persistent communication with C2 servers, generate DGA domains based on fixed seed algorithms based on the number of weeks and years, steal browser data, and provide additional payloads in the form of plugins that can manipulate HTML content, according to a TRAC Labs report at the beginning of February of this year.

“In particular, GhostWeaver can deploy Mintsloader as an additional payload via the sendPlugin command. Communication between GhostWeaver and its command and control (C2) servers is protected via TLS encryption using obfuscated X.509 certificates embedded directly in PowerShell.

The disclosure comes when Kroll reveals that he has revealed attempts made by threat actors to leverage Clickfix to ensure initial access through an ongoing campaign that leverages Clickfix.

Share This Article
Twitter Copy Link
Previous Article The best 7-day modifications to die in 2025 The best 7-day modifications to die in 2025
Next Article mm Future House announces Superintelligent AI agents to revolutionize scientific discovery

Latest News

mm

AI is giving pets a voice: The future of cat health care begins with one photo

Artificial intelligence is revolutionizing the way we care for animals.…

May 15, 2025
5 BCDR Essentials for Effective Ransom Defense

5 BCDR Essentials for Effective Ransom Defense

Ransomware has evolved into a deceptive, highly tuned, dangerous and…

May 15, 2025
mm

Anaconda launches the first unified AI platform to redefine enterprise-grade AI development

Anaconda Inc., a longtime leader in Python-based data science, has…

May 14, 2025
Microsoft fixed 78 flaws and exploited five zero-days. CVSS 10 bug affects Azure DevOps servers

Microsoft fixed 78 flaws and exploited five zero-days. CVSS 10 bug affects Azure DevOps servers

On Tuesday, Microsoft shipped fixes to address a total of…

May 14, 2025
mm

Why language models are “lost” in conversation

A new paper from Microsoft Research and Salesforce found that…

May 13, 2025

You Might Also Like

WordPress Plugin Vulnerability
Technology

ottokit WordPress Plugin Administrator Creation Vulnerability Vulnerability

3 Min Read
Researchers identify static vulnerabilities that allow data breach in rack:: Ruby servers
Technology

Researchers identify static vulnerabilities that allow data breach in rack:: Ruby servers

5 Min Read
mm
Technology

Are you feeling pressured to invest in AI? Good – you should be

7 Min Read
GRAPELOADER Malware Targeting European Diplomats
Technology

APT29 will deploy grey prober malware targeting European diplomats through wine tasting lures

6 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?