A new malspam campaign that uses Google’s DoubleClick domain to avoid detection and eventually distribute the remote access trojan (RAT) DesckVB RAT has been discovered by cybersecurity researchers.
According to a report published with The Hacker News by Huntress researchers Anna Pham and Adam Mooney, the lure passes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to flag as suspicious, before the victim ever reaches attacker-controlled infrastructure.
The victim is then put into a malspam kit that uses the victim’s email address to customize itself on the fly. The kit dynamically pulls in location information and company branding to make the site seem authentic without forcing the operators to create a lure by hand for each target.
This attack is notable because it makes these operations more scalable and economical by doing away with the requirement for each targeted business to have a custom kit read more about Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
