Remcos RAT Campaign Uses Trojanized VeraCrypt Installers to Steal Credentials
ID: bca35717-67d5-5721-ada8-482c6201063d
STIX ID: report--bca35717-67d5-5721-ada8-482c6201063d
Feed Name: GBHackers
AhnLab ASEC reports an active Remcos RAT campaign focused on South Korean users—particularly participants in illegal online gambling—using social‑engineered bait (fake “blocklist user” tools) and fraudulent VeraCrypt installers. The attack uses staged VBS and PowerShell downloaders, obfuscated payload placement (Base64 in JPG-like files), and a .NET injector that reports to Discord webhooks, decrypts and injects the Remcos payload into a legitimate process; Remcos provides credential theft, keylogging, screenshots, webcam/microphone surveillance, and remote control. Observed IOCs include distribution paths, randomized temp VBS files, and encrypted SETTINGS resources; recommended actions include isolating suspected systems, scanning and remediation, and credential resets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
