logo

Distribution of RAT Malware Disguised as a Gambling-related File

ID: 112ee899-b3f0-5701-9dd5-40c621afac3c

STIX ID: report--112ee899-b3f0-5701-9dd5-40c621afac3c

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-02-07

Date Updated: 2026-04-26

Author: yeeun

...
...

The report documents a malicious campaign where threat actors use shortcut/HTA files and obfuscated VBS/PowerShell to download decoy Excel documents (percent.xlsm) and payloads (darkss.exe — Venom RAT, Pandora_cryptered.exe — Pandora hVNC). It provides active indicators including C2 addresses (e.g., 193.***.***.253:4449, 85.209.176.158:7287), URLs, MD5 hashes, detection names, and shows the malware performs credential/keylogging theft and remote control activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.