# When the Trusted Screen Lies: A Week of Borrowed Legitimacy and Quiet Loaders


The threat actors who dominated this week's news didn't rely on zero-days or novel exploits. They relied on something cheaper and more durable: your willingness to trust a familiar interface. A login page. An antivirus app. A recruiter's instructions. A partner's VPN. The week's most interesting attacks weren't technically impressive — they were socially precise.


That's a harder problem to patch than a buffer overflow.


## Russia's Turn in the Crosshairs


There's a certain geopolitical irony baked into this week's threat roundup. Two distinct campaigns are hitting Russian targets hard — and neither is a nation-state operation. They're financially motivated criminal groups who've decided Russian organizations are worth the targeting risk.


The first is xplogs22, a cybercrime crew that's been quietly running since late 2023. They started with Formbook and Snake Keylogger before graduating to XWorm around mid-2025 — a trajectory that tracks with XWorm's increasing availability and modular flexibility. Their current campaign delivers XWorm via phishing to banking customers and corporate targets across Russia and CIS countries. Alongside that, Russian mobile users are getting hit with LunaSpy, an Android trojan wrapped in the skin of an antivirus application. The disguise is deliberate and effective: victims install what they believe is protection and hand over camera access, audio recording, screen capture, and sensitive data collection. The antivirus costume is a classic social engineering move, but it works because it inverts the victim's security instincts against them.


The second campaign is more significant. Toy Ghouls — also tracked as Bearlyfy and Labubu — has been running custom ransomware called GenieLocker against Russian manufacturing, financial services, retail, and tech firms since March. What makes this notable isn't the targeting; it's the infrastructure evolution. This group previously rented encryptors from the usual RaaS providers: RedAlert, LockBit, Babuk. Now they've built their own. GenieLocker has both PE and ELF variants, hitting Windows hosts and Linux/ESXi servers in coordinated fashion. When attackers stop renting tools and start building them, it signals maturity — and reduced operational exposure. No revenue share, no RaaS takedowns affecting their toolkit, no shared infrastructure to burn.


The initial access vector in one documented case? An OpenVPN connection from a trusted external partner's network. Classic trusted-relationship exploitation. The attackers didn't need to break in — they walked through a door that was already open.


## ClickFix Has Learned to Disappear


ClickFix has been covered extensively as an attack technique, but this week's variant deserves specific attention because it represents a meaningful technical advancement. The original pattern involved tricking users into pasting malicious commands into terminal windows or run dialogs. Annoying, but it left artifacts.


The newest variant, tracked by CyberProof, executes entirely through WebDAV. The victim pastes a single command into the Windows Run dialog. That command communicates with a remote WebDAV endpoint and invokes rundll32.exe to load a non-DLL payload — calling its first export by ordinal — without writing anything to disk. No artifact. No file for endpoint detection to catch. The payload files (named things like gc.key, j.pm, goog.ct) are served directly from the attacker's WebDAV share and executed in memory.


This is fileless malware delivered through a social engineering wrapper, and the combination is deliberately designed to frustrate both behavioral and signature-based detection. rundll32.exe is a legitimate Windows binary. WebDAV is a legitimate protocol. The payload never touches the filesystem in a way that conventional AV can catch. Defenders relying on file-based detection are effectively blind here.


What makes ClickFix attacks particularly pernicious is that they convert the victim into the payload delivery mechanism. No exploit needed. No phishing link to click. The user — believing they're following legitimate instructions — pastes the command themselves. Attribution gets muddier. Defense gets harder.


## CastleLoader Goes Crypto-Specific


CastleLoader has been a multi-purpose loader in previous campaigns, dropping CastleStealer and Python RATs via ClickFix-style lures. This week, Arctic Wolf documented a pivot: CastleLoader is now delivering Needle Stealer framework payloads with a specific focus on cryptocurrency targeting.


The toolkit now includes a Rust-based desktop wallet spoofer and a Golang-based malicious browser extension installer. The wallet spoofer tricks users into thinking they're interacting with their crypto wallet while silently capturing credentials or redirecting transactions. The browser extension installer establishes persistence at the browser level — harder to remove, harder to detect, and positioned to intercept web-based crypto activity continuously.


Arctic Wolf also identified a new shellcode loader variant spreading through digitally signed installers. Signed malware is a persistent headache because signature-based trust is foundational to Windows security. When attackers compromise or fraudulently obtain code signing certificates, they're exploiting that foundational trust directly.


The campaign name — Noidret — isn't the point. The point is the maturation of crypto-targeting tooling: purpose-built stealers, browser-level persistence, signed installers. This isn't opportunistic — it's a specialized operation against a high-value target class.


## What Defenders Are Actually Dealing With


Strip away the threat actor names and the campaign branding, and the week's themes are consistent:


Trusted relationships as attack vectors. GenieLocker got in via a partner's VPN. LunaSpy posed as security software. ClickFix impersonates legitimate instructions. The attack surface isn't just technical — it's the human and organizational trust model.


Fileless and memory-resident execution. ClickFix's WebDAV variant and CastleLoader's shellcode loader both prioritize leaving nothing on disk. Endpoint detection that relies on file scanning misses these. Behavioral monitoring — watching what processes do, not what files they touch — becomes essential.


Tool maturation among criminal groups. Toy Ghouls building GenieLocker rather than renting. CastleLoader delivering crypto-specific Rust and Go payloads. The criminal ecosystem is professionalizing faster than most enterprises are adapting.


---


## HackWire Analysis


The most underreported thread running through this week's incidents is what happens when criminal groups outgrow the Ransomware-as-a-Service model. For years, defenders and law enforcement leaned into RaaS takedowns as a meaningful disruption strategy — take down LockBit, disrupt dozens of affiliates simultaneously. That strategy is getting less effective as mature groups internalize their tooling.


Toy Ghouls' GenieLocker is a case study. By building their own encryptor, they eliminate their dependency on RaaS infrastructure that can be seized, their revenue share with developers, and their operational exposure through shared C2 infrastructure. The threat model for defenders shifts: you can no longer assume that a RaaS takedown touches this group at all.


The Russia-targeting angle also deserves scrutiny beyond the irony. These campaigns suggest that financially motivated criminal groups are increasingly comfortable targeting Russian entities — something that was historically constrained by the implicit protection many groups operating from CIS countries enjoyed. Whether that's a shifting risk calculus, actual geographic displacement of threat actors, or simply opportunism following money into Russian markets is unclear. But it's a pattern worth tracking.


The ClickFix fileless variant represents the more urgent operational concern for most defenders. WebDAV execution via rundll32.exe is not a technique that most enterprise security stacks are tuned to catch. If your detection relies primarily on file writes and signature scanning, you have a gap that's being actively exploited right now. Audit your RunDLL32 process behavior monitoring. Block or restrict WebDAV access where it's not required. And stop assuming that "no file written" means "no infection."


The crypto-targeting toolkit maturation is a separate problem with a different remediation path: hardware wallets, browser extension audits, and skepticism toward any installer that touches financial applications.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)