Just in:
SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // India plans own orbital space outpost, second after China // Haldwani purification row: Caste back on political centre-stage // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Putin holds talks with Pezeshkian in Bishkek // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Qatar economy contracts 7% as energy output slumps // Alpha Dhabi lifts MICAD commitment to $1 billion // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Trump rejects munitions fears as Iran clashes resume // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Adobe widens Saudi AI access with $4 billion programme // Xi reaches Cairo as China broadens Egypt engagement // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // What Shein’s $27bn IPO means for Mubadala // LatAm gushers and possible Venezuela exit a nightmare for Opec //

Trusted Intel tool turned against banks

 

A legitimate Intel storage utility has been repurposed in a highly targeted malware campaign that uses a little-known. NET mechanism to run hostile code inside a signed executable, giving attackers a quieter path into corporate networks and making detection far harder for many security products. The operation, identified as PhantomCLR, has been observed against financial institutions and other organisations across the Middle East and the wider EMEA region.

At the centre of the intrusion is IAStorHelp. exe, a genuine Intel Rapid Storage Technology component. Rather than tampering with the binary itself, the attackers package it with a malicious configuration file and supporting payloads. When the file set is opened, the trusted Intel program launches as expected, but the. NET runtime reads the rogue configuration alongside it and hands control to attacker-defined code before the application’s normal logic fully takes hold. Microsoft’s documentation shows that AppDomainManager can customise a domain before other managed code runs, which helps explain why the technique is so effective inside a legitimate process.

The delivery method appears built for deception rather than scale. The malware is typically wrapped inside a ZIP archive containing the signed Intel executable, a poisoned IAStorHelp. exe. config file, an obfuscated loader, an encrypted payload, a shortcut disguised as a PDF and a decoy document crafted to look official. One lure analysed by researchers used a “Work From Home Policy Updates” theme with Saudi government-style branding, indicating an effort to align the bait with regional political and workplace conditions. That suggests the operators are not casting a wide net but choosing victims carefully and shaping the social engineering to local expectations.

What makes the campaign notable is not only the use of a signed binary but the depth of the follow-on evasion. Researchers say the framework avoids altering the original Intel file, preserving its digital trust, and then relies on computation-heavy delays rather than ordinary sleep calls to frustrate sandboxes. One stage reportedly uses a 60-second prime-number routine, followed by an 892,007-iteration key-derivation process to unlock an encrypted payload. By the time the main malware becomes visible, automated tools may already have timed out or logged only what appears to be resource-heavy but harmless activity.

The malware also avoids some of the behaviours that security teams have spent years tuning their tools to catch. Instead of leaning on well-watched APIs such as VirtualAlloc or WriteProcessMemory, the attackers use a just-in-time compilation route to obtain executable memory and then pivot into shellcode from there. CYFIRMA’s analysis says the framework further uses direct system calls, reflective loading and API resolution methods designed to reduce obvious forensic artefacts. It also includes memory cleanup routines intended to erase traces after execution, raising the cost of incident response and post-breach analysis.

The network side of the campaign is built with similar care. Command-and-control traffic is said to pass through Amazon CloudFront infrastructure, masking the destination behind a cloud service that many enterprises already trust. That does not make the traffic invisible, but it does complicate simple blocking strategies that depend on crude domain or IP reputation lists. For banks, insurers and regional conglomerates that already rely on cloud-heavy business traffic, the overlap with normal network patterns may narrow the window for analysts to distinguish legitimate communications from malicious beaconing.

The technique itself is part of a broader shift in enterprise intrusion tradecraft. Security researchers have warned this year that AppDomainManager injection allows attackers to run code inside trusted. NET applications without exploiting a software flaw in the traditional sense. That makes the abuse attractive because it borrows the reputation of genuine software and turns ordinary configuration behaviour into an execution trigger. The PhantomCLR case shows how that concept can be operationalised in a more mature post-exploitation framework aimed at sectors where stealth, dwell time and credential access matter more than noisy disruption.


Also published on Medium.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Russia brings cryptocurrency market law into force // Dubai hotel provides free public co-working space // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Apple raises evidence-destruction claims against OpenAI // Alpha Dhabi lifts MICAD commitment to $1 billion // LatAm gushers and possible Venezuela exit a nightmare for Opec // Qatar economy contracts 7% as energy output slumps // Haldwani purification row: Caste back on political centre-stage // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // India plans own orbital space outpost, second after China // Drone strike damages Kuwait residential complex, no injuries //