logo

New Spear Phishing Attack Leveraging Argentine Federal Court Rulings to Covert RAT for Remote Access

ID: 709758c5-6445-52ac-8d64-6771da17401e

STIX ID: report--709758c5-6445-52ac-8d64-6771da17401e

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated spear-phishing campaign is targeting Argentina’s judicial sector by sending ZIP archives that contain a weaponized LNK file which launches PowerShell to run a batch loader that fetches a second-stage payload from GitHub; the final Rust-based RAT performs anti-analysis checks and provides encrypted C2, file exfiltration, credential harvesting, persistence, and the capability to deploy ransomware via modular DLLs, while presenting a convincing decoy court document to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.