RAT Distributed as UUEncoding (UUE) File
Essential information
- Published
- 11/06/2024 10:11
- Modified
- 11/06/2024 10:31
- Tags
- 2024-06-11 obfuscation persistence phishing rat remcos remote access
- Related entities
- 3 observables, 10 techniques (mitre), 1 malware
Description
This intelligence report describes a malicious operation where the Remcos Remote Access Trojan (RAT) is being disseminated through phishing emails containing an attachment exploiting the Unix-to-Unix Encoding (UUE) technique. The encoded file loads an obfuscated VBScript that fetches additional malicious components, leading to the deployment of the Remcos RAT on compromised systems. The report outlines the multi-stage infection process, providing technical details and indicators of compromise (IOCs) related to this campaign.