The attack embeds a remote-access trojan within a legitimate Windows process, allowing it to blend into normal endpoint activity This article explores executable files phishing. . It uses a deceptive legal-notice lure called “Resolución Denuncia Jurídica,” aimed at evoking fear and urgency.
When opened, the SVG redirects users to a fake Colombian judicial portal and creates a password-protected archive named DOC-16-ENE-2026 RESOLUCION DENUNCIA JURIDICA.7z. This is an instance of HTML smuggling, where malicious content is hidden within a file type that can evade email security filters more effectively than executable files. Phishing emails (source: trellix) use this technique called DLL sideloading, allowing malicious code to execute under a trusted application's guise. It establishes persistence through a Registry Run key, enabling the malware to restart automatically when the user logs into their account.
During execution, the loader decrypts an embedded payload found within its .rdata section. Even though AddInProcess32.exe remains listed in process lists, its memory contains DCRat code instead of its original instructions. It performs anti-analysis checks, delays execution to avoid sandbox environments, creates a mutex named DcRatMutex_qwqdanchun, bypasses AMSI protections, and attempts persistence.
Indicators of Compromise Type Indicator Description Email hash F205AB7E6AEFC10B9833D1A9A91BAD02 Phishing email carrying the judicial-themed lure Email filename ENVIO DE RESOLUCION DENUNCIA JUDICIAL RA-093-7397.eml Malicious phishing email file












