Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads
ID: dae1801c-6f0d-5b0d-bf75-79250efc192f
STIX ID: report--dae1801c-6f0d-5b0d-bf75-79250efc192f
Feed Name: cybersecurityNews.com
LevelBlue SpiderLabs observed a sophisticated, reusable multi-vector malware campaign that begins with obfuscated VBS launchers dropping a Base64 PowerShell loader which fetches PNG-embedded payloads from open directories on news4me.xyz; the embedded assembly (PhantomVAI) loads in memory and deploys Remcos RAT and a UAC-bypass DLL, enabling stealthy remote access and privilege escalation. The report identifies attacker infrastructure, examples of IOCs and infection chains, and recommends blocking execution from user-writable folders, enforcing constrained PowerShell, and network-level filtering to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
