The Judicial Decoy: Sophisticated Rust RAT Infiltrates Argentina’s Federal Courts
ID: 390dca5b-ce42-5aa2-8b87-5d6107c62c91
STIX ID: report--390dca5b-ce42-5aa2-8b87-5d6107c62c91
Feed Name: securityonline.info
Threat Score
A targeted spear-phishing campaign against Argentina's legal infrastructure deploys a Rust-based RAT via a weaponized LNK disguised as a PDF; the multi-stage chain uses a BAT loader and PowerShell bypass to fetch a GitHub-hosted payload that employs extensive anti-VM/anti-debugging checks, establishes a resilient modular C2, and includes commands for persistence, data harvesting/exfiltration, and file operations aimed at long-term infiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
