Executive Summary
A sophisticated multi-stage infection chain has been identified using malicious HTML Application (HTA) files disguised as VLC media presentations. The attack begins with an HTA file execution that utilizes VBScript and JavaScript to drop a primary loader, which subsequently fetches and executes the 'Lightlife' Remote Access Trojan (RAT). The malware is primarily designed for information theft, specifically targeting cryptocurrency wallet browser extensions and system metadata.
The technical workflow leverages living-off-the-land binaries (LOLBins) including mshta.exe, wmic.exe, and wscript.exe to evade traditional detection. Once executed, the PowerShell-based payload (lightlife.ps1) establishes persistence through registry modifications and utilizes the Telegram Bot API for exfiltration notifications. The infrastructure is hosted on a Russian C2 server (91.196.32[.]232), which serves decoy media files to distract users while the infection proceeds in the background.
This threat represents a significant risk to organizations and individuals managing digital assets. The use of fileless PowerShell execution, AMSI bypasses, and multi-stage delivery through authenticated tokens indicates a high level of operational maturity. Defenders should prioritize monitoring for anomalous HTA execution and suspicious PowerShell commands involving encoded payloads and external network requests.
