logo

Revenge is a Dish Best Served… Obfuscated?

ID: 71ca53d5-847f-5ad6-81a0-cfbda182f6df

STIX ID: report--71ca53d5-847f-5ad6-81a0-cfbda182f6df

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense analyzed a multi-stage VBS/HTA email-delivered downloader that fetches obfuscated scripts from an open directory and a WordPress-hosted path to install RevengeRAT (Base64 PE executed from memory) and WSHRAT (VBScript stealer). The loader achieves persistence via Run keys and stores an obfuscated Base64 PE in the registry for fileless execution; the report includes detailed IOCs (file hashes, mutex, C2 domains/IPs, registry keys) and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.