Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
A new malspam campaign that uses Google's DoubleClick domain to avoid detection and eventually distribute the remote access trojan (RAT) DesckVB RAT has been discovered by cybersecurity researchers.
According to a report published with The Hacker News by Huntress researchers Anna Pham and Adam Mooney, the lure passes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to flag as suspicious, before the victim ever reaches attacker-controlled infrastructure.
The victim is then put into a malspam kit that uses the victim's email address to customize itself on the fly. The kit dynamically pulls in location information and company branding to make the site seem authentic without forcing the operators to create a lure by hand for each target.
...

