logo

A Simple 'Payment is Underway' Phishing Email Downloads RATs from AWS, GitHub

ID: a7288584-c4c2-5da5-8f75-c2e75444fe22

STIX ID: report--a7288584-c4c2-5da5-8f75-c2e75444fe22

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-03-27

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Fortinet analysis describes a simple but effective phishing campaign that uses a malicious Java downloader hosted on legitimate services (AWS, GitHub) and obfuscated with Branchlock to deliver remote access trojans (VCURMS and STRRAT), a keylogger, and password-recovery malware. The attack begins with a 'Remittance Summary' email containing an image link to the Java payload, demonstrating how one-click phishing and use of public repositories can enable credential theft and remote access while evading detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.