Date: 08/17/2026
Severity: High
Summary
This DCRat campaign combines phishing with SVG attachment, DLL sideloading, and process hollowing to establish stealthy remote access while evading endpoint defenses. By abusing trusted Windows utilities and requiring user interaction, the malware blends into legitimate activity and enables in-memory execution. The campaign highlights the importance of threat hunting, module load monitoring, network correlation, and patch management to detect modern malware delivery techniques.
Indicators of Compromise (IOC) List
IP Address | 158.94.208.109 |
Hash | F205AB7E6AEFC10B9833D1A9A91BAD02
A3A471F1C7A605DD34AF49EF075E1251
13df3e065c421436bf0ac6fed3f9bb7f
d4bb45d3aef7a9161df4cadaeeba6a39
Acef69c68b8c3d3c3e1e53196a26ca60
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("158.94.208.109") or srcipaddress IN ("158.94.208.109") |
Detection Query 2 : | md5hash IN ("d4bb45d3aef7a9161df4cadaeeba6a39","F205AB7E6AEFC10B9833D1A9A91BAD02","Acef69c68b8c3d3c3e1e53196a26ca60","13df3e065c421436bf0ac6fed3f9bb7f","A3A471F1C7A605DD34AF49EF075E1251")
|
Reference:
https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/