Threats Tagged 'reflective loading'
View all threats tagged with 'reflective loading'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'reflective loading'
Click on any threat for detailed analysis and mitigation recommendations
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT 0 Between late July and mid-August 2026, multiple organizations were compromised by a sophisticated modular RAT disguised as a legitimate Exodus cryptocurrency wallet. Victims were tricked through fake PDFs or software updates delivered via JavaScript files that downloaded a tampered Windows Installer package. The installer deploys genuine Exodus wallet version 24.33.4 with three modified files that prevent the user interface from displaying while establishing persistent access. The payload includes six modules providing hidden VNC, SOCKS proxy, browser credential theft, file management, remote shell, and script execution capabilities. Communication occurs via Azure Table Storage as a dead drop mechanism, avoiding traditional command and control domains. The RAT maintains persistence through scheduled tasks executing hourly and includes mechanisms to bypass corporate proxy configurations. Join the discussion | AlienVault OTX General | 09/01/2026, 18:13:21 UTC Added: 09/02/2026, 11:52:17 UTC |
Signed Overwolf Binary Sideloads ValleyRAT Malware in India 0 A phishing campaign targets Indian organizations by impersonating the Indian Income Tax Department. Victims receive emails containing links to spoofed notice pages that download ZIP archives. These archives include a legitimately signed Overwolf executable and two hidden files: a malicious DLL and an encrypted binary. When executed, the signed binary side-loads the malicious DLL through DLL hijacking. The DLL is UPX-packed and modified with Astral-PE, and decrypts the binary file containing ValleyRAT. The payload uses modified RC4 encryption with a 115-byte key and deploys entirely in memory. Once active, ValleyRAT establishes persistence through scheduled tasks masquerading as OneDrive entries, marks dropped files as hidden and system files, and performs process hollowing into svchost.exe to evade detection before connecting to command and control infrastructure. Join the discussion | AlienVault OTX General | 08/18/2026, 15:23:42 UTC Added: 08/18/2026, 20:04:25 UTC |
Showing 1 to 2 of 2 results