Close Menu
    What's Hot

    Republicans Begin to Test the Limits of Trump’s Power by Flexing Their Own

    Georgia Republicans want Trump's endorsement — before it's too late

    The Afghanistan-Pakistan Border Is Still Unstable – Foreign Policy

    Facebook X (Twitter) Instagram
    Trending
    • Republicans Begin to Test the Limits of Trump’s Power by Flexing Their Own
    • Georgia Republicans want Trump's endorsement — before it's too late
    • The Afghanistan-Pakistan Border Is Still Unstable – Foreign Policy
    • Trump Says Iran War Is ‘Not a Big Thing’ for U.S.
    • Nvidia CEO Has a Simple Philosophy Behind Paying Workers
    • World Cup 2026: Why Harry Kane could play less minutes for England in the USA, Canada and Mexico this summer | Football News
    • Man Utd transfer news: Michael Carrick wants four more signings this summer after Ederson deal – Paper Talk | Football News
    • Proposed PGA Tour model includes 2 tracks of tournaments
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

    adminBy adminJune 3, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 03, 2026Malware / Microsoft Defender

    Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

    Cybersecurity researchers have flagged a new malspam campaign that makes use of Google’s DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT.

    “Before the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to treat as suspicious,” Huntress researchers Anna Pham and Adam Mooney said in a report shared with The Hacker News.

    “From there, the victim is passed into a malspam kit that personalizes itself on the fly using the victim’s email address, dynamically pulling in company branding and location details to make the page feel convincing without requiring the operators to handcraft a lure for each target.”

    What makes this attack noteworthy is that it eliminates the need for having a bespoke kit for each targeted organization, thereby making these operations more scalable and cost-effective. The end goal of the campaign is to drop DesckVB RAT, a .NET-based trojan that has been active in the wild since February 2026.

    Cybersecurity

    The attack begins when an unsuspecting user opens an HTML file that’s attached to a phishing email. The file triggers a meta-refresh browser redirect to a Google DoubleClick Campaign Manager click-tracking URL, from where the user is steered to another redirector, which decodes the Base64-encoded email address and leads the victim to a landing page containing a “Download PDF” button.

    Clicking the button causes the server to respond with a ZIP archive that initiates the rest of the infection chain. This is achieved by means of a JavaScript loader, whose main responsibility is to retrieve and execute a .NET RAT while flying under the radar. The script extracts and runs a PowerShell script, which then fetches a .NET loader from an external server.

    The loader acts as a stager that verifies it’s not being analyzed, neutralizes the machine’s security controls, sets up persistence, and then ultimately downloads and runs the RAT payload by using a technique called process hollowing that involves injecting the malware into Microsoft-signed processes.

    Once launched, the trojan communicates with a command-and-control (C2) server over raw TCP sockets, carries out system reconnaissance, and configures Microsoft Defender exclusions. The trojan also patches Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) at the native API level at the outset in an effort to blind Windows telemetry before persistence is established on the host by setting up Run and RunOnce Registry entries, along with placing a loader responsible for launching the RAT in the user’s Startup folder.

    Cybersecurity

    The malware comes with capabilities to extract data, run commands, and deploy additional payloads, granting the attackers full control over the infected machines, while simultaneously taking steps to fly under the radar by terminating and rebooting the machine if it detects an analysis tool or determines that it’s running in a sandboxed environment.

    “This is a strong reminder of why defence in depth matters,” Huntress said. “Configuring a Group Policy Object (GPO) in Active Directory to force script files such as .vbs, .hta, and .js to open in Notepad by default can stop a threat actor at the very first stage, preventing additional payloads from ever being dropped.”

    “On the email security front, organizations should consider deploying DMARC, DKIM, and SPF records to reduce the likelihood of spoofed or malicious emails reaching end users. Beyond that, an email gateway solution capable of sandboxing attachments and links before delivery adds another meaningful layer of protection.”

    Abused campaign Deliver DesckVB DoubleClick Google Malspam RAT
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleGwyneth Paltrow’s puzzling dairy substitute—arugula—takes off on social media like a rocket
    Next Article Tod Machover receives George Peabody Medal for contributions to music and technology | MIT News
    admin
    • Website

    Related Posts

    Lovable signs multi-year deal with Google Cloud to up usage 5x, source says

    June 3, 2026

    WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

    June 3, 2026

    Google parent Alphabet upsizes record-breaking equity raise to $85bn

    June 3, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Republicans Begin to Test the Limits of Trump’s Power by Flexing Their Own

    Georgia Republicans want Trump's endorsement — before it's too late

    The Afghanistan-Pakistan Border Is Still Unstable – Foreign Policy

    Trump Says Iran War Is ‘Not a Big Thing’ for U.S.

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by