logo

Threat actor abuses Gophish to deliver new PowerRAT and DCRAT

ID: 7b575195-afaa-52b0-9a1c-b0ae9bbc3ad6

STIX ID: report--7b575195-afaa-52b0-9a1c-b0ae9bbc3ad6

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2024-10-22

Date Updated: 2026-04-27

Author: Chetan Raghuprasad

...
...

Cisco Talos reports an active Gophish-based phishing campaign targeting Russian-speaking users that uses malicious Word macros and JavaScript-embedded HTML to deliver a memory-resident PowerShell RAT (PowerRAT) and Dark Crystal RAT (DCRAT). The report details delivery URLs and IPs, infection and persistence mechanisms (registry LOAD key, scheduled tasks, Defender exclusions), loader behaviors (GOLoader, SFXRAR), C2 endpoints, modular payload capabilities including data theft and remote control, and provides IOCs and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.