Cagey Phishing Campaign Delivers Multiple RATs to Steal Windows Data
ID: a86bd773-fdd7-589e-91af-6228a282dd5f
STIX ID: report--a86bd773-fdd7-589e-91af-6228a282dd5f
Feed Name: Dark Reading
Date Published: 2024-04-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Fortinet's FortiGuard Labs uncovered a corporate phishing campaign targeting Windows users that delivers VenomRAT v6 and other remote access trojans/stealers via obfuscated SVG attachments and ScrubCrypt-created batch files; the attack chain includes base64-embedded SVG payloads, unpacked ZIPs, BatCloak/PowerShell stages, AMSI/ETW bypasses, persistence mechanisms, C2 communication for plugin retrieval (Remcos, NanoCore, XWorm, and a crypto-wallet stealer), and published IOCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
