Modular RAT Campaign Steals Credentials and Captures Screenshots
ID: 166e0f8a-c074-5108-9e29-c05412db2fad
STIX ID: report--166e0f8a-c074-5108-9e29-c05412db2fad
Feed Name: GBHackers
Seqrite Labs identified "Operation GriefLure," a targeted spear-phishing campaign against senior executives in Vietnam and the Philippines that used highly convincing decoy documents and a modular, fileless RAT (sfsvc.exe with 360.dll) delivered via malicious LNK files; the malware performs credential theft, screenshots, process injection, persistence via DLL sideloading/NTFS ADS, and communicates with C2 infrastructure (e.g., whatsappcenter.com) — multiple file hashes and IOCs are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
