Listen to this Post

Cybercriminal Tactics Reach New Heights in 2025
In a chilling turn of events, cybersecurity researchers from Sophos have uncovered a dangerous new malware infection chain orchestrated by the notorious GOLD BLADE cybercriminal group. Operating under aliases like RedCurl, Red Wolf, and Earth Kapre, this group has long been known for precision-targeted phishing campaigns. Now, in July 2025, they’ve refined their attack methodology even further. Leveraging seemingly innocent job application files, they deploy a multi-stage payload using advanced sideloading and remote DLL execution. Their custom malware, dubbed RedLoader, is purpose-built to evade modern defenses and exfiltrate sensitive data from compromised Windows systems. The implications are serious — not only for cybersecurity experts but for HR teams and corporate staff who remain unsuspecting entry points in these schemes.
A Multi-Layered Attack That Exploits Trust and Familiarity
GOLD BLADE’s latest attack vector begins with an age-old tactic: phishing. This time, however, the weapon of choice is a convincingly disguised PDF, supposedly a cover letter, sent via trusted job portals like Indeed. Once opened, this document delivers a ZIP file to the target’s machine, cleverly hiding a malicious LNK file masked as another PDF. Upon activation, the shortcut silently runs conhost.exe, reaching out to remote infrastructure hosted on Cloudflare Workers through WebDAV. There, a renamed Adobe executable (CV-APP-2012-68907872.exe) is paired with a malicious DLL (netutils.dll). This duo enables classic DLL sideloading, where a legitimate-looking program loads a harmful payload in the background.
This first stage of infection installs a scheduled task (BrowserQE\BrowserQE_<encoded_computer_name>) to ensure persistence. That task, in turn, downloads the second-stage payload — an executable that maintains the same hash signature across multiple attacks. The malware uses system processes like PCALua.exe and conhost.exe to execute this stage, then opens a command-and-control (C2) channel for remote instructions and data theft. What makes this campaign stand out is the shift from script-based execution to standalone executables, showing a calculated evolution in malware delivery tactics. Sophos urges businesses to adopt tighter execution policies and utilize updated endpoint protections to guard against this sophisticated threat. The report identifies specific domains, file names, and hashes associated with RedLoader to help in threat detection and response.
What Undercode Say:
Evolution of a Threat Actor with Surgical Precision
GOLD BLADE’s latest campaign isn’t just an example of clever malware engineering — it’s a masterclass in psychological warfare. By targeting HR personnel through familiar platforms like Indeed, the attackers exploit trust at its most vulnerable point: human curiosity and routine job processes. The social engineering component is strong, with credible-looking PDFs acting as bait, while technical sophistication ensures the payload slips past basic antivirus filters undetected.
Why RedLoader Is a Game Changer
The use of Adobe’s signed binary (ADNotificationManager.exe) is significant. Not only does it provide the illusion of legitimacy, but the tactic also complicates detection. Most security tools whitelist signed binaries, making the malicious netutils.dll effectively invisible unless behavior-based detection is used. The first-stage infection focuses solely on persistence and silent setup, while the second-stage payload is modular, adaptable, and connects directly to C2 servers for exfiltration.
Cloudflare Workers as a Threat Vector
By deploying their infrastructure on Cloudflare Workers, the attackers benefit from a well-reputed, high-availability service that flies under the radar. These domains are difficult to blacklist due to the shared architecture, posing a new challenge for defenders. Moreover, the use of WebDAV as a transport mechanism adds another stealth layer, as it blends into regular network activity.
Dissecting the Infrastructure: Indicators That Matter
The threat intelligence reveals three key domains (automatinghrservices.workers.dev, quiet.msftlivecloudsrv.workers.dev, and live.airemoteplant.workers.dev), all hosted on Cloudflare. Their usage for C2 operations highlights how attackers now prefer resilient, decentralized infrastructure that can be quickly re-deployed if compromised. The malware itself is identifiable through static signatures and hash patterns that remain consistent — a clue defenders can leverage if they act quickly.
The Persistence Mechanism Is Alarmingly Durable
The creation of a scheduled task using encoded system names helps GOLD BLADE remain entrenched on infected machines. This technique allows the group to maintain access over long periods, especially on systems that don’t enforce tight execution policies in AppData or Downloads folders.
Lessons for Corporate Defenders
This campaign should be a wake-up call for IT teams. Security measures must go beyond signature-based detection. Implementing Group Policy Objects (GPOs) that restrict LNK file execution in common user folders is a crucial defense step. Behavior-based endpoint detection, such as tracking suspicious child processes from conhost.exe, is becoming indispensable.
Reinvention, Not Repetition
What makes GOLD BLADE especially dangerous is their ability to adapt. The group’s pivot from script-based payloads to standalone executables in this campaign is a direct response to previous detection methods. Their flexibility keeps them a step ahead of traditional defenses, emphasizing the need for dynamic, threat-informed security postures.
Call for Vigilance
Enterprises must invest in user training, especially for HR teams. Recognizing suspicious files, understanding the risks of external downloads, and verifying unexpected applications are vital first-line defenses. Even with the best endpoint protection, human error remains a gaping vulnerability.
🔍 Fact Checker Results:
✅ The use of signed Adobe binaries for DLL sideloading was verified by Sophos
✅ C2 domains hosted on Cloudflare Workers match Sophos threat intelligence reports
✅ The LNK file attack chain, including WebDAV access and scheduled tasks, is confirmed
📊 Prediction:
🔮 GOLD BLADE is unlikely to stop here. Given their adaptability, future campaigns may integrate AI-generated job applications or exploit new cloud platforms beyond Cloudflare.
🔮 Expect more multi-stage payloads using legitimate binaries to bypass endpoint security.
🔮 Enterprises failing to restrict LNK execution and sideloading behaviors could become major breach headlines by late 2025.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




