{"id":1147,"date":"2026-06-03T22:11:52","date_gmt":"2026-06-03T22:11:52","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1147"},"modified":"2026-06-03T22:11:52","modified_gmt":"2026-06-03T22:11:52","slug":"google-doubleclick-abused-in-new-malspam-campaign-to-deliver-desckvb-rat","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1147","title":{"rendered":"Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 03, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Microsoft Defender<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhpQ6QXxFH4zkfeHGdcm1WXVcNXMpyJm-1dlZLbFCdp6rKDRhuwICzYaKaR-rCpn61qod6A1F98PZejZbmYuxaUXPJLXQffoaniCkqgyqR1-p7gClpj4PYibjzIDHk8_Vw4ag00EYPCM3Nz1G0Hvzuf6wBV-HzDFoSiYDEEdjPU45Bk_rIlGk9dJ_MMVuue\/s1700-e365\/ad-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged a new malspam campaign that makes use of Google&#8217;s DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named <b>DesckVB RAT<\/b>.<\/p>\n<p>\u00abBefore the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to treat as suspicious,\u00bb Huntress researchers Anna Pham and Adam Mooney <a href=\"https:\/\/www.huntress.com\/blog\/malspam-to-deskcvb-rat-delivery-chain-analysis\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>\u00abFrom there, the victim is passed into a malspam kit that personalizes itself on the fly using the victim&#8217;s email address, dynamically pulling in company branding and location details to make the page feel convincing without requiring the operators to handcraft a lure for each target.\u00bb<\/p>\n<p>What makes this attack noteworthy is that it eliminates the need for having a bespoke kit for each targeted organization, thereby making these operations more scalable and cost-effective. The end goal of the campaign is to drop DesckVB RAT, a .NET-based trojan that has been active in the wild since February 2026.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The attack begins when an unsuspecting user opens an HTML file that&#8217;s attached to a phishing email. The file triggers a meta-refresh browser redirect to a Google DoubleClick Campaign Manager click-tracking URL, from where the user is steered to another redirector, which decodes the Base64-encoded email address and leads the victim to a landing page containing a \u00abDownload PDF\u00bb button.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Clicking the button causes the server to respond with a ZIP archive that initiates the rest of the infection chain. This is achieved by means of a JavaScript loader, whose main responsibility is to retrieve and execute a .NET RAT while flying under the radar. The script extracts and runs a PowerShell script, which then fetches a .NET loader from an external server.<\/p>\n<p>The loader acts as a stager that verifies it&#8217;s not being analyzed, neutralizes the machine&#8217;s security controls, sets up persistence, and then ultimately downloads and runs the RAT payload by using a technique called process hollowing that involves injecting the malware into Microsoft-signed processes.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8AQKvnK0LGEfzrfFDdXjalMc_sc0hx3WmK521U1JIZFoWI1FTwBWpjmFxOrerr5jqAqhoD1DLvoZf9r7Q9ClbVr-2Ga_Cq1dMKH_BA7ChBt24FHgL0o3IPPCmWeV4Idzi4SW_Y4vke0k4GduaMQZhE6wE1R2lkayfsI1mF8zgD0XxgP5k4K21CUZ4sozK\/s1700-e365\/malspam.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8AQKvnK0LGEfzrfFDdXjalMc_sc0hx3WmK521U1JIZFoWI1FTwBWpjmFxOrerr5jqAqhoD1DLvoZf9r7Q9ClbVr-2Ga_Cq1dMKH_BA7ChBt24FHgL0o3IPPCmWeV4Idzi4SW_Y4vke0k4GduaMQZhE6wE1R2lkayfsI1mF8zgD0XxgP5k4K21CUZ4sozK\/s1700-e365\/malspam.jpg\" alt=\"\" border=\"0\" data-original-height=\"540\" data-original-width=\"960\"\/><\/a><\/div>\n<p>Once launched, the trojan communicates with a command-and-control (C2) server over raw TCP sockets, carries out system reconnaissance, and configures Microsoft Defender exclusions. The trojan also patches Antimalware Scan Interface (<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/amsi\/antimalware-scan-interface-portal\">AMSI<\/a>) and Event Tracing for Windows (<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/test\/wpt\/event-tracing-for-windows\">ETW<\/a>) at the native API level at the outset in an effort to blind Windows telemetry before persistence is established on the host by setting up Run and RunOnce Registry entries, along with placing a loader responsible for launching the RAT in the user&#8217;s Startup folder.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The malware comes with capabilities to extract data, run commands, and deploy additional payloads, granting the attackers full control over the infected machines, while simultaneously taking steps to fly under the radar by terminating and rebooting the machine if it detects an analysis tool or determines that it&#8217;s running in a sandboxed environment.<\/p>\n<p>\u00abThis is a strong reminder of why defence in depth matters,\u00bb Huntress said. \u00abConfiguring a Group Policy Object (GPO) in Active Directory to force script files such as .vbs, .hta, and .js to open in Notepad by default can stop a threat actor at the very first stage, preventing additional payloads from ever being dropped.\u00bb<\/p>\n<p>\u00abOn the email security front, organizations should consider deploying DMARC, DKIM, and SPF records to reduce the likelihood of spoofed or malicious emails reaching end users. Beyond that, an email gateway solution capable of sandboxing attachments and links before delivery adds another meaningful layer of protection.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 03, 2026Malware \/ Microsoft Defender Cybersecurity researchers have flagged a new malspam campaign that makes use of Google&#8217;s DoubleClick domain as a way to evade detection and ultimately&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1148,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1233,6,529,1892,1890,2,1891,264],"class_list":["post-1147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abused","tag-campaign","tag-deliver","tag-desckvb","tag-doubleclick","tag-google","tag-malspam","tag-rat"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1147"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1147\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1148"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}