Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malspam Campaign Exploits Google DoubleClick

New Malspam Campaign Exploits Google DoubleClick

Posted on June 3, 2026 By CWS

Cybersecurity experts have identified a sophisticated malspam campaign that leverages Google’s DoubleClick domain to bypass security measures and deploy a remote access trojan (RAT) known as DesckVB RAT.

According to researchers Anna Pham and Adam Mooney from Huntress, the attack initiates by rerouting potential victims through DoubleClick, a domain owned by Google, which many security systems consider legitimate and therefore non-threatening.

The campaign’s unique strategy involves using a malspam kit that customizes itself by dynamically incorporating the victim’s email address, company branding, and location information, eliminating the need for tailored lures for each target.

Exploiting Google DoubleClick

The exploitation begins when a recipient opens an HTML file attached to a phishing email, prompting a redirect to a Google DoubleClick Campaign Manager URL. From there, the victim is led to a landing page that cleverly disguises itself with company-specific details.

The page features a deceptive ‘Download PDF’ button, which, when clicked, delivers a ZIP file containing a JavaScript loader. This loader initiates the download and execution of the .NET-based DesckVB RAT, effectively bypassing many security measures.

Technical Aspects of the Attack

The JavaScript loader is designed to remain undetected, executing a PowerShell script that retrieves a .NET loader. This loader verifies it is not being analyzed, disables security features, and ensures persistence by employing a process hollowing technique to inject the malware into legitimate processes.

Once activated, the RAT communicates with a command-and-control server, performing system reconnaissance and altering Microsoft Defender settings. It also patches native APIs to obscure its presence from Windows telemetry.

Implications and Prevention

The DesckVB RAT provides attackers with extensive control over compromised systems, capable of extracting data and executing commands. It includes mechanisms to hide its activities, such as detecting and responding to analysis environments by terminating operations.

To counter such threats, Huntress emphasizes the importance of a multi-layered defense strategy. Implementing Group Policy Objects to open script files in Notepad by default can thwart the initial stages of an attack. Additionally, deploying DMARC, DKIM, and SPF records can help prevent malicious emails.

On the organizational level, utilizing an email gateway that sandboxes attachments and links before delivery can add another protective layer, significantly reducing the risk of successful cyber attacks.

The Hacker News Tags:cyber threat, Cybersecurity, DesckVB RAT, email security, Google DoubleClick, Huntress researchers, Malspam, Malware, Phishing, remote access trojan

Post navigation

Previous Post: Google Gemini Vulnerability Exploited via Messaging Apps
Next Post: HazyBeacon Exploits AWS for Covert Cyber Operations

Related Posts

AI Becomes Russia’s New Cyber Weapon in War on Ukraine AI Becomes Russia’s New Cyber Weapon in War on Ukraine The Hacker News
Cloud Password Managers Face Security Challenges Cloud Password Managers Face Security Challenges The Hacker News
Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks The Hacker News
Critical Cisco Vulnerability in Secure Workload API Patched Critical Cisco Vulnerability in Secure Workload API Patched The Hacker News
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale The Hacker News
SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark