Stealthy MintsLoader Unleashes GhostWeaver RAT: Evading Detection with DGA and TLS in Sophisticated Phishing Campaign


# MintsLoader Malware Delivers GhostWeaver RAT Through Multi-Stage Attacks

Security researchers have identified that the malware loader MintsLoader is being used to distribute GhostWeaver, a sophisticated PowerShell-based remote access trojan. According to Recorded Future’s Insikt Group, MintsLoader operates through a complex infection chain utilizing obfuscated JavaScript and PowerShell scripts while employing advanced evasion techniques.

MintsLoader has been active since early 2023, primarily distributing various payloads including StealC and modified BOINC clients. The loader has become a tool of choice for cybercriminal groups operating e-crime services such as SocGholish (FakeUpdates) and LandUpdate808 (TAG-124), targeting industrial, legal, and energy sectors through phishing campaigns and fake browser updates.

Recent attack waves have incorporated the ClickFix social engineering tactic, tricking victims into executing malicious code distributed through spam emails. While MintsLoader functions solely as a loader, its effectiveness stems from robust sandbox evasion capabilities and a domain generation algorithm (DGA) that creates C2 domains based on the execution date.

GhostWeaver, the payload delivered by MintsLoader, maintains persistent C2 communication using DGA domains generated through a fixed-seed algorithm based on week number and year. It can deploy plugins to steal browser data and manipulate HTML content. Notably, GhostWeaver can deploy MintsLoader as an additional payload and secures C2 communication through TLS encryption with an obfuscated, self-signed X.509 certificate.

In a related development, Kroll has identified a campaign called CLEARFAKE that uses ClickFix to trick victims into running MSHTA commands that deploy Lumma Stealer malware.

Share This Article