Threats Tagged 'process hollowing'
View all threats tagged with 'process hollowing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'process hollowing'
Click on any threat for detailed analysis and mitigation recommendations
Between July and August 2026, a sophisticated campaign targeted organizations across East and Southeast Asia using Japanese and Korean-language phishing emails disguised as product damage complaints. Recipients were directed to fake document-sharing websites that delivered ZIP files containing malware. The archives contained executables with double extensions and DLLs implementing various loader techniques including customized Donut loaders, Python interpreters, AMSI/ETW bypasses, process hollowing, and BYOVD attacks using vulnerable Lenovo drivers. Despite varying loader implementations, the final payloads consistently delivered PureRAT or PureLogs malware families. The campaign demonstrated advanced evasion techniques by frequently changing loader structures while maintaining the same core payloads, effectively bypassing hash-based detection methods. Infrastructure analysis revealed common sending patterns through PHP Swift Mailer and shared Feedback-ID values across campaigns. Join the discussion | AlienVault OTX General | 09/25/2026, 15:41:27 UTC Added: 09/28/2026, 14:03:04 UTC |
A phishing campaign impersonates sales staff from overseas companies, sending emails with malicious GZ compressed files. Extracting these files delivers an injector executable that uses multiple UAC bypass techniques and exploits a vulnerable driver (DCRCVDrv.sys) to disable security products at the kernel level. The injector then uses process hollowing to inject PhantomStealer malware into a legitimate process. PhantomStealer steals sensitive information including keystrokes, screenshots, browser credentials, cryptocurrency wallet data, and manipulates clipboard contents to replace wallet addresses with attacker-controlled ones. Join the discussion | AlienVault OTX General | 08/19/2026, 07:28:55 UTC Added: 08/19/2026, 10:04:41 UTC |
A phishing campaign targets Indian organizations by impersonating the Indian Income Tax Department. Victims receive emails containing links to spoofed notice pages that download ZIP archives. These archives include a legitimately signed Overwolf executable and two hidden files: a malicious DLL and an encrypted binary. When executed, the signed binary side-loads the malicious DLL through DLL hijacking. The DLL is UPX-packed and modified with Astral-PE, and decrypts the binary file containing ValleyRAT. The payload uses modified RC4 encryption with a 115-byte key and deploys entirely in memory. Once active, ValleyRAT establishes persistence through scheduled tasks masquerading as OneDrive entries, marks dropped files as hidden and system files, and performs process hollowing into svchost.exe to evade detection before connecting to command and control infrastructure. Join the discussion | AlienVault OTX General | 08/18/2026, 15:23:42 UTC Added: 08/18/2026, 20:04:25 UTC |
A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support. Join the discussion | AlienVault OTX General | 07/01/2026, 16:52:43 UTC Added: 07/02/2026, 07:06:43 UTC |
A sophisticated phishing campaign was identified distributing multiple malware families through a multi-stage loader utilizing steganography and fileless techniques. The infection chain begins with archive attachments containing files disguised as financial documents, primarily targeting Indian organizations using names related to GST, NEFT, RTGS, and IMPS transactions. The loader employs in-memory execution to avoid disk-based artifacts and uses embedded .NET Bitmap objects to conceal payloads. Various malware families have been deployed including Remcos RAT, Agent Tesla, MassLogger, Phantom Stealer, Dark Cloud, Red Line Stealer, Snake keyloggers, Formbook, and xworm. The final payloads establish persistence through registry Run keys, perform process hollowing, steal browser credentials, record audio and webcam, and exfiltrate data to command-and-control infrastructure. The campaign exhibits characteristics of a loader-as-a-service operation serving multiple threat actors globally. Join the discussion | AlienVault OTX General | 06/23/2026, 17:35:20 UTC Added: 06/23/2026, 19:39:17 UTC |
A sophisticated malware campaign exploits growing interest in artificial intelligence by distributing malicious files disguised as AI-related learning resources and technical guides. The attack employs an exceptionally complex multi-stage infection chain beginning with compressed archives containing LNK shortcuts and hidden PDF files. Through multiple layers of obfuscation involving PowerShell scripts, batch files, and AutoHotkey loaders, the campaign establishes persistent access and deploys two distinct .NET Remote Access Trojans including AsyncRAT. The intermediate scripts extensively use Simplified Chinese variable names and exhibit coding patterns suggesting AI-assisted development, with cultural references to Chinese mythology used as symbolic aliases for Windows API calls. The attack implements advanced techniques including process hollowing, reflective DLL injection, and scheduled task persistence while actively disabling Windows Defender exclusions to facilitate execution. Join the discussion | AlienVault OTX General | 06/11/2026, 16:31:56 UTC Added: 06/15/2026, 19:30:18 UTC |
Microsoft Defender Experts identified an active cryptojacking campaign leveraging AI-assisted delivery mechanisms alongside traditional SEO poisoning. Attackers create fake download sites impersonating trusted utilities like CrystalDiskInfo, HWMonitor, and FurMark, targeting users with high-performance GPUs. Victims download ZIP archives containing legitimate executables bundled with malicious DLLs that establish persistence via ScreenConnect remote access tools. The operation employs sophisticated techniques including DLL sideloading, process hollowing into Microsoft-signed .NET binaries, and comprehensive defense evasion. Beyond cryptocurrency mining, the campaign establishes persistent remote access that could enable data theft, lateral movement, or ransomware deployment. The threat actors deliberately target PC enthusiasts and hardware-focused users most likely to own discrete GPUs suitable for profitable mining operations. Join the discussion | AlienVault OTX General | 05/27/2026, 00:04:11 UTC Added: 05/27/2026, 14:03:32 UTC |
A sophisticated phishing campaign distributes a PureLogs variant through deceptive purchase order emails containing malicious JavaScript files. The attack chain employs obfuscated JavaScript that drops PowerShell scripts, which then use process hollowing techniques to inject .NET modules into legitimate Windows processes. The malware communicates with command-and-control infrastructure to download additional plugins. PureLogs collects extensive sensitive information including credentials from web browsers, cryptocurrency wallets, email clients, Discord, and various applications. It also captures screenshots, system information, and clipboard data. The collected data is compressed, encrypted with AES, and exfiltrated to remote servers. The campaign demonstrates advanced evasion techniques through fileless execution, multiple encryption layers, and abuse of trusted processes like MsBuild.exe, making detection challenging for traditional security solutions. Join the discussion | AlienVault OTX General | 05/26/2026, 15:20:05 UTC Added: 05/27/2026, 14:03:32 UTC |
APT37 conducted a sophisticated social engineering campaign utilizing Facebook accounts claiming locations in Pyongyang and Pyongsong, North Korea, to conduct reconnaissance and build trust with targets. After establishing relationships through Facebook Messenger, the threat actor migrated conversations to Telegram and employed pretexting tactics, claiming to share encrypted PDF documents containing military weapons information. Victims were persuaded to install a tampered Wondershare PDFelement installer that executed embedded shellcode for initial compromise. The attack chain delivered follow-on commands through a JPG-disguised payload hosted on a compromised Japanese real estate website. The malware abused Zoho WorkDrive OAuth2 APIs as C2 channels, exfiltrating screenshots, documents, system information, and audio files. The campaign employed multiple evasion techniques including code cave injection, process hollowing into legitimate dism.exe, XOR encryption layers, and fileless in-memory execution. Join the discussion | AlienVault OTX General | 04/14/2026, 08:55:08 UTC Added: 04/14/2026, 09:32:02 UTC |
This analysis examines a sophisticated multi-stage infection chain utilizing Agent Tesla malware. The attack begins with a phishing email containing a RAR file, which includes an obfuscated JSE file. This initial stage triggers a series of script-based evasions, leading to the download and decryption of a PowerShell script. The malware then employs process hollowing to inject its payload into a legitimate Windows process, evading detection. Before exfiltrating data, the malware performs anti-analysis checks to avoid security software and virtual environments. Finally, Agent Tesla harvests sensitive information, including browser cookies and contacts, exfiltrating the data via SMTP to a command-and-control server. Join the discussion | AlienVault OTX General | 02/25/2026, 20:01:58 UTC Added: 02/25/2026, 20:40:38 UTC |
Showing 1 to 10 of 19 results