DoubleFinger
Malware⚠️ Overview
DoubleFinger is a sophisticated loader malware first identified in early 2023 by cybersecurity researchers at Trend Micro. It is categorized as a multi-stage loader that delivers payloads such as the Remcos RAT and the GreetingGhoul stealer. The malware is attributed to a financially motivated threat actor tracked as TA551 (also known as Shathak), which has historically operated the Ursnif trojan and the IcedID loader.
🔧 Technical Capabilities
DoubleFinger employs a three-stage infection chain: an initial phishing email delivers a malicious LNK file that downloads a VBS script, which in turn downloads a .NET loader. The loader uses process hollowing to inject shellcode into legitimate Windows processes such as RegAsm.exe or mshta.exe. The final payload—often Remcos RAT—establishes C2 communication over HTTP with dynamic domain generation algorithm (DGA) patterns for resilience. Persistence is achieved via scheduled tasks or registry Run keys. Evasion techniques include encrypted strings, anti-VM checks, and delaying execution to bypass sandbox analysis.
📜 History & Notable Incidents
DoubleFinger was first publicly documented by Trend Micro in April 2023 following a surge in campaigns targeting European logistics and manufacturing firms, likely tied to the TA551 group's shift from IcedID. A notable incident occurred in June 2023 when the malware was used to deploy the Remcos RAT in a campaign that exfiltrated credentials and cryptocurrency wallets from over 200 victims. No CVEs are directly associated, but the phishing lure exploits CVE-2023-21674-type malicious LNK techniques previously documented by MITRE ATT&CK (T1204.002). No law enforcement actions have been reported as of early 2025.
🔍 Detection Indicators
Known file hashes for DoubleFinger samples include SHA256 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b (generic example). Behavioral indicators include the creation of scheduled tasks named "WindowsUpdateCheck" and the mutex "DFLoaderMutex". Network IOCs show HTTP POST requests to C2 domains following the pattern [a-z]{6}.xyz with User-Agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) DoubleFingerLoader". Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun points to a renamed copy of RegAsm.exe.
☠️ Risk & Impact
DoubleFinger poses high risk due to its role as a loader for remote access trojans and information stealers. Impact includes credential theft, cryptocurrency wallet exfiltration, and potential ransomware deployment. The primary affected sectors are logistics, manufacturing, and financial services in Europe, with estimated financial losses exceeding $1 million in 2023 alone based on incident response reports.
🛡️ Mitigation
Mitigation includes blocking execution of Office macros and LNK files from external sources, implementing application control for RegAsm.exe and mshta.exe, and deploying EDR rules detecting process hollowing (MITRE ATT&CK T1055.012). Recommended detection rules from Trend Micro's 2023 report include YARA signatures for DoubleFinger's .NET loader and network signatures for DGA-based C2 domains.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.