216.73.216.6

New Campaign Uses Remcos RAT to Exploit Victims

· Published 08/11/2024 18:33 · Modified 08/11/2024 19:22

Export JSON

Essential information

Published
08/11/2024 18:33
Modified
08/11/2024 19:22
Tags
2024-11-08 CVE-2017-0199 phishing powershell process-hollowing rat remcos
Related entities
2 observables, 1 malware

Description

A campaign utilizing has been detected. The attack begins with an email containing a malicious Excel document that exploits . When opened, it downloads and executes an HTA file, which in turn downloads and runs a malicious EXE. This EXE uses to load and execute obfuscated code, employing various anti-analysis techniques. The malware performs process hollowing to inject into a new process, maintaining persistence through registry modifications. then communicates with its C2 server, collecting system information and awaiting further commands. The has extensive capabilities for remote control and data exfiltration from the victim's device.

External references