Operation Covert Access: Rust RAT Infiltrates Argentina’s Judiciary
ID: d09dc83e-036b-57ce-9047-5a7381fea6e6
STIX ID: report--d09dc83e-036b-57ce-9047-5a7381fea6e6
Feed Name: securityonline.info
Operation Covert Access is a targeted cyber-espionage campaign against Argentina’s judicial system that leverages spear-phishing ZIP attachments containing malicious LNK files to run hidden PowerShell commands and fetch a Rust-based Remote Access Trojan from GitHub; the RAT hides as msedge_proxy.exe, performs VM and analysis-tool checks to evade detection, supports modular commands for persistence and data theft, and includes encryption routines that could enable ransomware-like operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
