RST TI Report Digest: 19 Jan 2026
ID: 7dd449a6-5d6d-54b3-a80a-9fdd4bc8b66c
STIX ID: report--7dd449a6-5d6d-54b3-a80a-9fdd4bc8b66c
Feed Name: RST Cloud Blog
Threat Score
The report details a ConvertMate malware campaign that distributes a dropper (ConvertMate.exe) via malvertising and fake converter apps; once installed it deploys RAT payloads, uses revoked code-signing certificates and scheduled tasks for persistence, employs timestomp for evasion, communicates with C2 servers, and includes a large set of IoCs (domains, URLs, and numerous SHA256 hashes) for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
