logo

Activity Targeting Crypto Asset Exchangers for Parallax RAT Infection

ID: 989e4054-203c-5d57-93b0-372a85ba2359

STIX ID: report--989e4054-203c-5d57-93b0-372a85ba2359

Feed Name: JPCERT Blog

Threat Score
70/100

Date Published: 2023-04-20

Date Updated: 2026-04-19

Author: JPCERT/CC

...
...

JPCERT/CC investigated a February 2023 campaign that delivered Parallax RAT to a crypto-asset exchanger via OneNote files linked from spam emails. The attack chain: Google Drive link → ZIP → OneNote with embedded/obfuscated VBS → PowerShell downloader (Latest.pdf, dx.txt, angle.exe) which disables UAC and Defender exclusions; Parallax RAT achieves persistence (Startup\Milk.exe), injects into pipanel.exe, performs keylogging and clipboard theft, and communicates with C2 (144.202.9.245:80). The report includes related tooling (NetSupport, GuLoader, IRC bot), server URLs and multiple file hashes for IOC hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.