PureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
ID: 6388c388-a6e1-5ad1-93c2-d507ccde2058
STIX ID: report--6388c388-a6e1-5ad1-93c2-d507ccde2058
Feed Name: TrendAI Security Blog
Threat Score
Trend Micro analysis of an active PureRAT campaign shows actors using job-seeker-themed phishing archives containing a Foxit-disguised executable and malicious msimg32.dll to perform DLL side-loading, extract a bundled Python runtime, run a base64-decoded shellcode loader, establish persistence, and exfiltrate browser data; the report provides IoCs (hashes, C2 IPs/URLs), certificate/JA3 details, and hunting queries for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
