Microsoft warns of RAT delivered through trojanized gaming utilities
ID: 1129a662-8972-572d-9456-99afb56126b3
STIX ID: report--1129a662-8972-572d-9456-99afb56126b3
Feed Name: Security Affairs
Microsoft warns of a campaign that lures users into running trojanized gaming utilities distributed via browsers and chat platforms to deploy a stealthy multi-purpose RAT. The attackers used a malicious downloader that ran a portable Java runtime to execute a harmful JAR, leveraged PowerShell and LOLBins (cmstp.exe) for stealth, modified Microsoft Defender exclusions, and established persistence via scheduled tasks and startup scripts; the RAT connected to C2 79.110.49.15 and Microsoft published related IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
