216.73.216.6

Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans

· Published 22/10/2024 21:56 · Modified 23/10/2024 08:49

Export JSON

Essential information

Published
22/10/2024 21:56
Modified
23/10/2024 08:49
Tags
2024-10-22 darkcrystal rat dcrat gophish html smuggling phishing powerrat remote access trojan russian-speaking
Related entities
2 observables, 13 techniques (mitre), 3 malware, 1 others

Description

A new campaign targeting users employs the open-source framework to deliver and a novel called . The attack utilizes modular infection chains, either through malicious Microsoft Word documents or HTML files with embedded JavaScript. The campaign exploits to send emails and deploy the malware. The infection process involves multiple stages, including the use of Visual Basic macros, HTML applications, and PowerShell scripts. Both and have capabilities for system reconnaissance, data exfiltration, and remote control. The attackers use various techniques to evade detection, such as and nested self-extracting archives.

External references