logo

Modular RAT Campaign Steals Credentials and Captures Screenshots

ID: 166e0f8a-c074-5108-9e29-c05412db2fad

STIX ID: report--166e0f8a-c074-5108-9e29-c05412db2fad

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

Seqrite Labs identified "Operation GriefLure," a targeted spear-phishing campaign against senior executives in Vietnam and the Philippines that used highly convincing decoy documents and a modular, fileless RAT (sfsvc.exe with 360.dll) delivered via malicious LNK files; the malware performs credential theft, screenshots, process injection, persistence via DLL sideloading/NTFS ADS, and communicates with C2 infrastructure (e.g., whatsappcenter.com) — multiple file hashes and IOCs are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.