Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malspam Campaign Exploits Google DoubleClick

New Malspam Campaign Exploits Google DoubleClick

Posted on June 3, 2026 By CWS

Cybersecurity experts have identified a sophisticated malspam campaign that leverages Google’s DoubleClick domain to bypass security measures and deploy a remote access trojan (RAT) known as DesckVB RAT.

According to researchers Anna Pham and Adam Mooney from Huntress, the attack initiates by rerouting potential victims through DoubleClick, a domain owned by Google, which many security systems consider legitimate and therefore non-threatening.

The campaign’s unique strategy involves using a malspam kit that customizes itself by dynamically incorporating the victim’s email address, company branding, and location information, eliminating the need for tailored lures for each target.

Exploiting Google DoubleClick

The exploitation begins when a recipient opens an HTML file attached to a phishing email, prompting a redirect to a Google DoubleClick Campaign Manager URL. From there, the victim is led to a landing page that cleverly disguises itself with company-specific details.

The page features a deceptive ‘Download PDF’ button, which, when clicked, delivers a ZIP file containing a JavaScript loader. This loader initiates the download and execution of the .NET-based DesckVB RAT, effectively bypassing many security measures.

Technical Aspects of the Attack

The JavaScript loader is designed to remain undetected, executing a PowerShell script that retrieves a .NET loader. This loader verifies it is not being analyzed, disables security features, and ensures persistence by employing a process hollowing technique to inject the malware into legitimate processes.

Once activated, the RAT communicates with a command-and-control server, performing system reconnaissance and altering Microsoft Defender settings. It also patches native APIs to obscure its presence from Windows telemetry.

Implications and Prevention

The DesckVB RAT provides attackers with extensive control over compromised systems, capable of extracting data and executing commands. It includes mechanisms to hide its activities, such as detecting and responding to analysis environments by terminating operations.

To counter such threats, Huntress emphasizes the importance of a multi-layered defense strategy. Implementing Group Policy Objects to open script files in Notepad by default can thwart the initial stages of an attack. Additionally, deploying DMARC, DKIM, and SPF records can help prevent malicious emails.

On the organizational level, utilizing an email gateway that sandboxes attachments and links before delivery can add another protective layer, significantly reducing the risk of successful cyber attacks.

The Hacker News Tags:cyber threat, Cybersecurity, DesckVB RAT, email security, Google DoubleClick, Huntress researchers, Malspam, Malware, Phishing, remote access trojan

Post navigation

Previous Post: Google Gemini Vulnerability Exploited via Messaging Apps

Related Posts

U.S. DoJ Seizes Fraud Domain Behind .6 Million Bank Account Takeover Scheme U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme The Hacker News
Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems The Hacker News
Cybercrime Groups Exploit Vishing for SaaS Attacks Cybercrime Groups Exploit Vishing for SaaS Attacks The Hacker News
LiteLLM Attack Exploits Developer Machines for Credentials LiteLLM Attack Exploits Developer Machines for Credentials The Hacker News
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads The Hacker News
Google Ordered to Pay 4M for Misusing Android Users’ Cellular Data Without Permission Google Ordered to Pay $314M for Misusing Android Users’ Cellular Data Without Permission The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Malspam Campaign Exploits Google DoubleClick
  • Google Gemini Vulnerability Exploited via Messaging Apps
  • Google Gemini Vulnerability Exposed by Notifications
  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Malspam Campaign Exploits Google DoubleClick
  • Google Gemini Vulnerability Exploited via Messaging Apps
  • Google Gemini Vulnerability Exposed by Notifications
  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark