MintsLoader Malware Deploys GhostWeaver via Phishing Campaign and ClickFix Exploit

MintsLoader Malware Deploys GhostWeaver via Phishing Campaign and ClickFix Exploit

New Cyber Threat “MintsLoader” Unleashes Covert Malware Operation with GhostWeaver Backdoor

A newly identified cyber threat dubbed MintsLoader is raising alarms across the cybersecurity community. Acting as a stealthy delivery framework, MintsLoader is responsible for deploying a previously unseen backdoor named GhostWeaver, which is now at the center of a surge in targeted intrusions.

Over the past several weeks, threat intelligence teams have recorded a sharp rise in cyberattacks aimed primarily at the finance and healthcare sectors. These attacks utilize a hybrid infiltration strategy that blends traditional phishing lures with a novel user manipulation technique known as ClickFix exploitation.

Victim targeting often begins with polished phishing messages, engineered to mimic legitimate business communications. Attached documents — usually Word or PDF files — masquerade as financial statements, patient information, or executive memos. Upon opening, recipients encounter prompts to enable macros or interact with fake notifications. These actions quietly initiate the first phase of the infection.

According to analysts at Recorded Future, MintsLoader’s activity first came to light following anomalous traffic across several monitored networks. Their investigation uncovered the use of ClickFix, a social engineering tactic designed to exploit human behavior. The trick? Convincing users to resolve phony system errors through specific click sequences, effectively sidestepping most awareness training.

Once the malware gains a foothold, GhostWeaver is deployed to establish long-term access, siphoning off highly sensitive data — from login credentials to financial and proprietary business information.

Security operations centers have flagged cases where the malware operated undetected for extended periods, a testament to its minimal digital footprint and advanced evasion methods.


Inside the Attack Chain: How MintsLoader Works

MintsLoader initiates its multi-layered assault through embedded VBA macros hidden within routine-looking Office files. These macros are tailored to trigger a cascade of actions, methodically advancing the malware from initial execution to full backdoor deployment — all while keeping defenders in the dark.

Threat Analysis: MintsLoader’s Tactical Blueprint
Source: Recorded Future

Upon execution, MintsLoader initiates a covert sequence by retrieving a disguised PowerShell script that initially appears innocuous. Hidden beneath this surface is a highly obfuscated payload designed to avoid immediate detection.

For example, the script embeds a block of compressed Base64-encoded data:

Once decompressed, this payload dynamically assembles and executes additional code, establishing contact with a remote control infrastructure. Notably, the malware leverages a domain generation algorithm (DGA) to continuously cycle through domain names — a tactic designed to sidestep static blacklist defenses and sustain command-and-control access even if some domains are blocked.

After the initial handshake with the C2 server, MintsLoader proceeds to fetch and run GhostWeaver, a modular backdoor engineered for long-term stealth. GhostWeaver embeds itself deep within the system by manipulating the Windows Task Scheduler and modifying key registry entries — ensuring it remains operational through reboots and persists across sessions.

This stage of the compromise marks the transition from access to entrenchment, turning the infected system into a silent beachhead for ongoing data exfiltration and lateral movement.

Inside the ClickFix Chain: How MintsLoader Embeds, Deceives, and Persists
Source: Recorded Future

MintsLoader’s infection strategy is a masterclass in persistence engineering and user deception. Its operational flow reveals a layered approach, embedding itself deep within systems and adapting to resistance with surprising agility.

At the core of its resilience is the creation of multiple footholds across the host environment — from startup folders to scheduled tasks and registry autoruns — all carefully orchestrated to reinitiate the malware even after system reboots or partial cleanups.

One of the most advanced capabilities lies in its stealth disabling of endpoint defenses. MintsLoader leverages Windows Management Instrumentation (WMI) to identify and manipulate defensive tools at a low level, undermining protection without triggering alerts.

But what truly sets this threat apart is the ClickFix mechanism — a cutting-edge social engineering strategy that plays on user behavior. Rather than delivering traditional phishing lures, ClickFix generates authentic-looking system prompts, styled to mimic trusted elements such as Windows update dialogs or security alerts.

These prompts appear periodically and subtly condition users to click without scrutiny. Each interaction is weaponized — either escalating privileges silently or deploying additional malware modules. The interface realism is striking, enough to fool even security-aware users through simple repetition and familiarity.

Because the ClickFix technique subverts user instincts rather than technical vulnerabilities, it requires a new kind of defense posture. Experts now advise that organizations:

  • Enforce strict application whitelisting policies
  • Disable all non-essential macro functionality in Microsoft Office
  • Keep endpoint protection software fully updated
  • Launch targeted awareness campaigns to retrain users on spotting interaction-based attacks

For defenders, a suite of indicators of compromise — including malicious file hashes and anomalous network behaviors — has been released to aid in early detection and containment.

More Articles & Posts