PULSE NAME
Operation DualScript: Multi-Stage PowerShell Malware Targets Crypto
WHITE AlienVault 2026-03-31 Modified: 2026-03-31
12
IOCs
MEDIUM VOLUME
Operation DualScript is a sophisticated multi-stage malware campaign targeting cryptocurrency and financial activities. It utilizes Windows Scheduled Tasks, VBScript launchers, and PowerShell execution to maintain persistence while minimizing disk artifacts. The attack operates through two parallel chains: a web-based PowerShell loader deploying a cryptocurrency clipboard hijacker, and a secondary chain executing the RetroRAT implant in memory. RetroRAT monitors user activity, captures keystrokes, and tracks interactions with financial services to harvest sensitive information. The malware employs various anti-analysis techniques and establishes a command-and-control channel for remote access and data exfiltration. This campaign highlights the growing abuse of trusted system utilities and in-memory execution techniques to evade traditional detection mechanisms.
Indicators of Compromise (6 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 163c38bd7ff7dd27e88eaef1a7a4819f 2026-03-31
FileHash-MD5 173b27e7541427929da72ebf37c6db8e 2026-03-31
FileHash-MD5 1dc82fd02a0db3e338128b6f587d7122 2026-03-31
FileHash-MD5 243af69d85550232da45f5a30703a4a3 2026-03-31
FileHash-MD5 43cac07a501e7a717023e0fa8f6111e0 2026-03-31
FileHash-MD5 7546ada1e3144371724db209ba4c5f37 2026-03-31