Sophos researchers uncover a new attack chain used by the GOLD BLADE group involving sophisticated LNK files and DLL sideloading techniques to deploy RedLoader malware. This evolving method demonstrates how threat actors combine previous tactics to evade detection and establish command and control communications. #GOLD BLADE #RedLoader
Keypoints
- The attack begins with a malicious PDF link leading to a ZIP archive containing a disguised LNK file.
- The LNK file executes conhost.exe, which contacts a CloudFlare domain to load a signed, masquerading executable.
- RedLoader stage 1 downloads a malicious DLL and creates a scheduled task for stage 2 deployment.
- Stage 2 involves a victim-specific executable communicating with a command and control server.
- Organizations can mitigate these threats by blocking LNK files in common directories and deploying specialized detection tools.
Read More: https://news.sophos.com/en-us/2025/07/29/gold-blade-remote-dll-sideloading-attack-deploys-redloader/