TAG-150 Attack Chain Deploys DenoRAT Malware
ID: 47a3c604-4197-5591-8475-e388d3f8b991
STIX ID: report--47a3c604-4197-5591-8475-e388d3f8b991
Feed Name: securityonline.info
A confirmed TAG-150 campaign targeting the finance sector used a ClickFix social engineering lure to execute a malicious MSI that bootstrapped the Deno runtime and staged DinDoor and DenoRAT; these then delivered a Python-based reflective loader that runs NightshadeC2 in memory to steal credentials and browser data. The report details persistence via registry Run keys, Deno FFI usage for low-level operations, HTTP polling C2, obfuscation of stagers, DLL injection to bypass App-Bound Encryption, and defensive recommendations (monitor Deno installs, block unauthorized MSIs, hunt for anomalous PowerShell and registry changes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
