Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Wisconsin and Nill Collective say in the lawsuit that Miami induces an inappropriately induced footballer

Federal judge blocks Trump’s efforts to prevent Harvard from hosting foreign students

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Mintsloader drops GhostWeaver via phishing, Clickfix – using DGA, TLS for stealth attacks
Identity

Mintsloader drops GhostWeaver via phishing, Clickfix – using DGA, TLS for stealth attacks

userBy userMay 2, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 2, 2025Ravi LakshmananMalware/Threat Intelligence

Mintsloader drops GhostWeaver via phishing, Clickfix

A malware loader known as Mintsloader is used to deliver PowerShell-based remote access Trojans called GhostWeaver.

“Mintsloader works through a multi-stage infection chain containing obfuscated JavaScript and Powershell scripts,” the Insikt group at Future said in a report shared with Hacker News.

“Malware employs sandbox and virtual machine avoidance technologies for domain generation algorithms (DGAs) and HTTP-based command-and-control (C2) communication.”

Distributed phishing and drive-by download campaigns have been detected wild since early 2023 for each orange cyber defense. Loaders have been observed to provide modified versions such as various subsequent payloads such as STEALC and Berkeley Open Infrastructure (BOINC) clients for network computing.

Cybersecurity

Malware is also used by threat actors who run e-Crime services such as Socgholish (aka FakeUpdates) and Landupdate808 (aka TAG-124) and is distributed via phishing emails targeting the industry, legal and energy sectors, as well as fake browser update prompts.

Mintsloader drops GhostWeaver via phishing, Clickfix

With a notable twist, recent attack waves employ an increasingly popular social engineering tactic called Clickfix to trick site visitors and copy and run malicious JavaScript and PowerShell code. Links to Clickfix pages will be distributed via spam email.

“Mintsloader only functions as a loader without supplemental features, but its main strength lies in its sandbox and virtual machine avoidance technology, as well as its DGA implementation that derives the C2 domain based on the date it was run,” said Future, recorded.

Use DGA and TLS for stealth attacks

These features, coupled with obfuscation techniques, can prevent threat actors from analyzing and complicate detection efforts. The main responsibility of the malware is to use PowerShell scripts to download the next stage payload from the DGA domain via HTTP.

GhostWeaver is designed to maintain persistent communication with C2 servers, generate DGA domains based on fixed seed algorithms based on the number of weeks and years, steal browser data, and provide additional payloads in the form of plugins that can manipulate HTML content, according to a TRAC Labs report at the beginning of February of this year.

Cybersecurity

“In particular, GhostWeaver can deploy Mintsloader as an additional payload via the sendPlugin command. Communication between GhostWeaver and its command and control (C2) servers is protected via TLS encryption using obfuscated X.509 certificates embedded directly in PowerShell.

The disclosure comes when Kroll reveals that he has revealed attempts made by threat actors to leverage Clickfix to ensure initial access through an ongoing campaign that leverages Clickfix.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBelfast launches UK hubs to drive innovation in digital twin technology
Next Article NHS rolls out 5 min nivolumab JAB for 15 cancers
user
  • Website

Related Posts

Qilin ransomware adds “Cole Lawyer” feature that puts pressure on victims for larger ransoms

June 20, 2025

Television in Iranian states hijacked mid-distance broadcasts amid geopolitical tensions. $90 million stolen from Crypto Heist

June 20, 2025

Successful In-house SOC 6 steps up to 24 hours a day, 365 days a year

June 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Wisconsin and Nill Collective say in the lawsuit that Miami induces an inappropriately induced footballer

Federal judge blocks Trump’s efforts to prevent Harvard from hosting foreign students

View the double: 15 twins who graduated from the same New York High School

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Elon Musk’s AI startup Xai will increase bond yields to 12.5% ​​with a $5 billion debt hike due to weak investor demand

Meta hires safe bipartisan executives after CEO Ilya Sutskever rejects $32 billion acquisition offer

Meta Earth Network 2.0: Pioneering Web3 Innovation with Rewards and Global Events

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.