Threat actors increasingly used Virtual Hard Disk (.vhd) files in phishing and malware delivery chains, replacing earlier ISO and IMG containers to improve evasion and execution. AhnLab documented a Qakbot campaign in which an HTML attachment generated a password-protected archive containing a VHD; when mounted, the image exposed a malicious LNK and scripts that ultimately launched rundll32 to load a DLL, inject into wermgr.exe, contact command-and-control servers, and enable follow-on payload delivery and financial data theft. Check Point separately observed the Bumblebee loader adopting VHD-based delivery with PowerShell download logic before later alternating between ISO and VHD containers with embedded DLLs, while tailoring second-stage payloads to victim environments.
Forensic analysis of a malicious sample named invoice.vhd showed why the format is attractive to operators: the mounted image contained a lure file, invoice.pdf.lnk, that launched obfuscated PowerShell to fetch and execute an HTA payload from transfer[.]sh, and the VHD preserved deleted artifacts revealing repeated reuse of the same container for JavaScript, VBS, SCR, EXE, BAT, and PIF payload staging. Residual files in $RECYCLE.BIN and metadata such as an IndexerVolumeGuid linked the image to broader attacker tradecraft, including prior payload distribution through Discord CDN links and recurring VBS-to-PowerShell execution chains, underscoring how VHD files can both bypass Mark of the Web protections and serve as reusable malware delivery containers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The visible lure file invoice.pdf.lnk inside the malicious VHD was timestamped 2023-05-01 10:39:50. The shortcut masqueraded with a Microsoft Edge icon and launched obfuscated PowerShell that downloaded and executed an HTA payload from transfer[.]sh.
Metadata in the analyzed invoice.vhd sample shows the VHD container was created on a Windows 10 system. The footer timestamp recorded the creation time as 2022-10-26 20:59:21.
Until early July 2022, Bumblebee command-and-control servers often accepted only the first unique client_id from a victim public IP address. Check Point observed that this behavior was later disabled, increasing successful victim connections and C2 traffic.
Check Point reported that in June 2022 the Bumblebee loader changed its delivery chain from ISO files to VHD files containing PowerShell download logic, before later reverting to embedded DLL delivery. The change marked an evolution in how the malware was packaged and delivered to victims.
The analyst created a YARA rule combining VHD magic bytes with the retained IndexerVolumeGuid value {BE882B07-1D3C-4C58-9D29-14A8C4AE35E5} to identify future related malware containers. The article recommended using the rule for retroactive and live hunting on platforms such as VirusTotal.
Analysis of deleted artifacts in $RECYCLE.BIN showed the same VHD had been reused across multiple dates from 2022 into 2023 to stage and delete payloads including JS, VBS, SCR, EXE, BAT, and PIF files. YARA matches on remnants also exposed historical Discord CDN payload links and repeated VBS-to-PowerShell tradecraft.
AhnLab reported that Qakbot was being distributed through phishing emails using HTML attachments that generated password-protected archives containing VHD files. When mounted, the VHD exposed LNK and script files that ultimately loaded a malicious DLL via rundll32.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
forensicitguy.github.io
Open sourceasec.ahnlab.com
Open sourceresearch.checkpoint.com
Open sourcebazaar.abuse.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.