216.73.216.6

VHDs Used to Distribute VenomRAT and Other Malware

· Published 14/03/2025 10:16 · Modified 14/03/2025 19:29

Export JSON

Essential information

Published
14/03/2025 10:16
Modified
14/03/2025 19:29
Tags
2025-03-14 aes encryption keylogger obfuscation persistence phishing powershell venomrat vhd
Related entities
11 techniques (mitre), 1 malware

Description

A campaign is utilizing virtual hard disk () image files to deliver malware. The attack begins with a purchase order-themed email containing a ZIP archive with a file. When opened, the mounts as a drive and executes a heavily obfuscated batch script. This script employs to perform malicious activities, including dropping files in the Startup folder for , modifying registries, and connecting to Pastebin for C2 communication. The malware creates a DataLogs.conf file to capture keystrokes and sensitive data, which is then exfiltrated to the C2 server. The campaign also utilizes and multiple layers of to evade detection.

External references