Remcos RAT Distributed via Webhards
ID: d96a3f8a-6645-5ff1-93af-8105ea8a3703
STIX ID: report--d96a3f8a-6645-5ff1-93af-8105ea8a3703
Feed Name: ASEC
AhnLab ASEC detected an active campaign distributing Remcos RAT in South Korea by disguising malware as game installers on webhards and torrents. The attackers include malicious VBS with a fake Game.exe that executes ffmpeg.exe, which splits a "sexyz" string to extract an encrypted binary and key from test.jpg, injects code into explorer.exe, then downloads Remcos from a C2 and injects it into ServiceModelReg.exe; the report provides file detections, MD5 hashes and URLs as IOCs and advises users to avoid running executables from file-sharing sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
