Hackers Distributing Malicious VBS/PowerShell RAT Chain Via Multiple DuckDNS Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft.

The chain relies on Visual Basic Script, or VBS, and PowerShell, two tools present on business computers, making an infection appear less unusual.

Campaign operators use several DuckDNS hosts, a layered malware delivery chain that supplies multiple addresses to deliver or support the attack against potential victims.

Once a victim runs the script, the activity can progress from a small launcher to a hidden payload built for 64-bit Windows systems.

Since the initial files use familiar Windows features, employees and defenses may treat activity as ordinary unless behavior is checked closely.

Threat researcher Anurag identified the activity and noted that two observed VBS files were identical.

Anurag said in a report shared with Cyber Security News (CSN) that the script decrypts an encrypted PowerShell stage, which then prepares the final remote access tool.

The danger is not limited to a single stolen password. The payload can collect browser data, record keystrokes, copy clipboard contents, and try to weaken built-in protections.

That mix gives attackers a route to personal accounts, workplace services, and sensitive information that may be pasted during daily work.

Malicious VBS and PowerShell RAT Chain Uses DuckDNS Hosts

The observed VBS stage is heavily obscured, a tactic meant to make quick inspection difficult.

After it runs, it unlocks a PowerShell component protected with AES-256 encryption. The next stage extracts an x64 payload and calls a .NET helper to place malicious code inside AppLaunch.exe.

This technique, called process hollowing, lets attackers run their code inside a process that can look legitimate to a hurried user or basic security check.

Readers can see how similar concealment works in this process hollowing attack overview, where a normal process is started and its memory is replaced before execution continues.

The campaign also appears able to reach one of its hosts through a direct IP address, providing another path if a domain is disrupted.

The payload is designed to keep working after a restart by placing itself in the Windows Startup folder under a misleading name. It also attempts to add exclusions in Microsoft Defender, which could reduce detection.

A related PowerShell backdoor malware attack shows why script-based threats deserve attention even when the first file looks small.

Credential Theft and Defensive Steps

Browser credentials and cookies are valuable because they can give criminals access to email, business portals, and other services without immediately needing a password.

Keystroke and clipboard collection expand that risk, potentially capturing passwords, one-time codes, messages, or payment details as they are entered or copied.

The reported keylogger stores collected material locally before it is likely sent onward. The malware is also associated with command-and-control communications on port 4577.

This combination of collection, persistence, and remote contact turns an initial script execution into a broader account and privacy incident.

Organizations should use the table below to block confirmed infrastructure at web, DNS, and network controls, then hunt across endpoints for evidence of the observed intrusion.

Security teams should review unexpected PowerShell activity, especially scripts that are encoded, hidden, or followed by unusual child processes.

Users should avoid opening script files received unexpectedly, even when they arrive in archives or appear to be routine documents.

Administrators can reduce exposure by limiting script execution where it is not required, maintaining endpoint protection, and investigating Defender exclusion changes promptly.

Coverage of browser credential theft techniques also underlines the value of using multi-factor authentication and quickly revoking exposed sessions.

If a system matches any of the indicators below, it should be isolated from the network and examined for follow-on activity.

Resetting passwords alone may not be enough if browser cookies or active sessions were taken, so affected accounts should be reviewed and invalidated as part of incident response.

Indicators of compromise (IoCs):-

Type Indicator Description
VBS SHA-256 8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96 Hash of the observed VBS samples
File name envifa.vbs Observed malicious VBS file
File name sostener2.vbs Observed malicious VBS file
Final payload SHA-256 7a3c619827557de9a3687daa137f772f40e1bba1a4ca32bac1b06557f42ce522 Hash of the final payload
Process-hollowing helper SHA-256 1932a80706489d55ae779ad1edfe0d0beb0239d0fc7bb10f99f89bc804ad3407 Hash of the .NET helper
Domain serversniperxx[.]duckdns[.]org DuckDNS host
Domain asegurar2026nuevo[.]duckdns[.]org DuckDNS host
Domain asegurar2026[.]duckdns[.]org DuckDNS host
Domain 2seguro2025[.]duckdns[.]org DuckDNS host
Domain www[.]2seguro2025[.]duckdns[.]org DuckDNS host
IP address 181.237.42[.]61 Accessible infrastructure address
Likely C2 serversniperxx[.]duckdns[.]org:4577 Suspected command-and-control endpoint
Persistence path %APPDATA%MicrosoftWindowsStart MenuProgramsStartupWindowsDefender.exe Startup persistence location
Keylogger storage C:ProgramDataSniperLogs Local keylogger data location

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world