Weaponized Shipping Documents Spread Remcos RAT in Stealthy Malware Campaign
ID: 689fdac5-244c-5279-b37f-a0f330d97158
STIX ID: report--689fdac5-244c-5279-b37f-a0f330d97158
Feed Name: GBHackers
A targeted phishing campaign impersonating Vietnamese shipping companies delivers a fileless Remcos RAT by using Word documents that load a remote RTF exploiting CVE-2017-11882; the RTF executes shellcode which runs a VBScript containing Base64-encoded PowerShell that downloads a .NET module (hidden in an image) to persist via Task Scheduler and inject the Remcos agent into memory using process hollowing, providing extensive surveillance and remote-control capabilities while evading file-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
