216.73.217.22

PureHVNC Deployed via Python Multi-stage Loader

· Published 09/08/2024 11:25 · Modified 09/08/2024 11:39

Export JSON

Essential information

Published
09/08/2024 11:25
Modified
09/08/2024 11:39
Tags
2024-08-09 asyncrat phishing purehvnc rat venomrat xworm
Related entities
18 observables, 10 techniques (mitre), 4 malware

Description

FortiGuard Labs uncovered a sophisticated attack campaign utilizing multiple obfuscation and evasion techniques to distribute and execute various malware, including , , , and . The campaign starts with a email containing a malicious attachment that initiates a series of harmful activities. All the malware employs packing and obfuscation tools like Kramer, donut, and laZzzy to conceal their presence. The analysis focuses on the malware, which collects victim information, targets crypto wallets, password managers, and two-factor authenticators, and can execute additional plugins for remote desktop control and execution.

External references