The malware loader called MintsLoader has been used to deliver a remote PowerShell-based trojan known as GhostWeaver . Phishing and drive-by download campaigns distributing MintsLoader have been detected since early 2023, according to Orange Cyberdefense .

See also: Phishing campaign targets WooCommerce administrators
The loader has been observed delivering various malicious payloads, including StealC and a modified version of the BOINC (Berkeley Open Infrastructure for Network Computing) client . The malware has also been used by cybercriminals operating e-crime services such as SocGholish (also known as FakeUpdates) and LandUpdate808 (also known as TAG-124) , who distribute the payloads via phishing emails targeting the industrial, legal, and energy sectors, as well as via fake browser update prompts.
In a notable development, recent waves of attacks are leveraging an increasingly common social engineering technique called ClickFixto trick website visitors into copying and executing malicious JavaScript and PowerShell code. Links to ClickFix pages are distributed via spam emails.
See also: New phishing emails imitate Google to steal credentials
These features, combined with blocking and obfuscation techniques, allow cybercriminals to make analysis difficult and complicate threat detection. The main role of the malware is to download the next stage of the malicious payload from a domain generated via DGA (Domain Generation Algorithm), using a PowerShell script over HTTP.

GhostWeaver , according to a report by TRAC Labs in February, is designed to maintain persistent communication with the command and control (C2) server, create DGA domains based on a fixed seed algorithm that uses the week and year, and deliver additional malicious payloads in the form of plugins that can intercept data from browsers and modify HTML content .
This revelation comes as Kroll disclosed that threat actors are attempting to gain initial access through an ongoing campaign codenamed CLEARFAKE , which leverages the ClickFix technique to trick victims into executing MSHTA commands, which ultimately install the Lumma Stealer malware .
See also: Beware – phishing email passes Google and Gmail checks
A related point is that techniques such as Domain Generation Algorithm (DGA) make it extremely difficult to detect and block communication with C2 servers. DGA domains are constantly changing and dynamically created, meaning that traditional filtering methods such as blacklisting are not sufficient. Furthermore, the use of tools such as PowerShell and MSHTA is a popular tactic for bypassing antivirus, as these are legitimate Windows tools that, when used maliciously, often go undetected.
Source: thehackernews
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
