
A new multi-stage loader called double finger A sophisticated attack targeting users in Europe, the United States, and Latin America was observed delivering a cryptocurrency thief dubbed GreetingGhoul.
“When a victim opens a malicious PIF attachment within an email message, DoubleFinger is deployed on the target machine, ultimately executing DoubleFinger’s first loader stage,” says Kaspersky researcher Sergey Lozhkin. said in a report on Monday.
The attack launching point is a modified version of espexe.exe (which refers to the Microsoft Windows Economic Service Provider application) designed to run shellcode that retrieves PNG image files from the image hosting service Imgur.
This image utilizes steganography to hide an encrypted payload, triggering a four-step compromise chain and ultimately running the GreetingGhoul stealer on the infected host.

GreetingGhoul is notable for using Microsoft Edge WebView2 to create a counterfeit overlay on top of legitimate cryptocurrency wallets, siphoning credentials entered by unsuspecting users.
In addition to dropping GreetingGhoul, DoubleFinger has also been found to distribute Remcos RAT, a commercial Trojan widely used by threat actors to attack organizations in Europe and Ukraine in recent months. It has been.
The analysis “revealed advanced techniques and skills in crimeware development similar to advanced persistent threats (APTs),” Rozkin noted.
“The multi-stage shellcode-style loader with steganography, the use of Windows COM interfaces for stealth execution, and the implementation of process doppelgänging for injection into remote processes are all well-crafted complexities. It shows good crimeware.”