DCRat Malware Hits Windows with Remote Access, Keylogging, Screen Capture, and File Theft Capabilities
ID: 5b29f1b3-8437-5801-bb38-2b611fdfa3e1
STIX ID: report--5b29f1b3-8437-5801-bb38-2b611fdfa3e1
Feed Name: Cyber Press
**Executive Summary:** A targeted phishing campaign is deploying the modular DCRat RAT against Windows users (predominantly in Colombia) via password-protected ZIPs that execute obfuscated scripts which retrieve a steganography-embedded payload; the malware supports modular plugins, credential harvesting, keylogging, persistence, and remote control. The report includes anti-analysis details (virtual machine checks, AMSI bypass), full attack chain description, and multiple IoCs (paste URLs, image archive, SHA-256 hashes, and a C2 IP), and notes that Fortinet products can detect and block the threat when signatures and engines are current.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
