Hackers Deploy Modular RAT With Credential Theft and Screenshot Capture Capabilities
ID: 26fbad35-e90e-5485-97fe-b1e894d98af3
STIX ID: report--26fbad35-e90e-5485-97fe-b1e894d98af3
Feed Name: cybersecurityNews.com
Threat Score
Operation GriefLure is a coordinated, modular RAT campaign targeting senior executives and investigators in Vietnam’s telecom sector and compliance staff in the Philippine healthcare sector; it delivers a stealthy credential‑stealing and screenshot‑capturing implant via nested spear‑phishing archives, uses bulletproof hosting (whatsappcenter.com / 38.54.122.188) for C2, and includes multiple IoCs (SHA256 hashes, domain, IP) and recommended defensive actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
