Remcos RAT Being Distributed to Korean Users
ID: 84b0984d-cb65-5f8d-84f1-2e9743e4357b
STIX ID: report--84b0984d-cb65-5f8d-84f1-2e9743e4357b
Feed Name: ASEC
Threat Score
AhnLab ASEC reports an active Remcos RAT campaign targeting users in South Korea that impersonates gambling 'blocklist lookup' tools and VeraCrypt installers. The actors use multi-stage obfuscated VBS/PowerShell droppers, a .NET injector (which exfiltrates logs via Discord webhooks) and injects Remcos into legitimate processes; the report includes configuration examples, Korean-language artifacts, and IOCs (MD5s, URLs, IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
