Threat Group Using Rare Data Transfer Tactic in New RemcosRAT Campaign
ID: a931fb50-5983-50a0-abf5-9a02714c5201
STIX ID: report--a931fb50-5983-50a0-abf5-9a02714c5201
Feed Name: Dark Reading
Threat Score
*Uptycs researchers report that UNC-0050 is conducting a campaign against Ukrainian government organizations using RemcosRAT delivered via a .lnk → 6.hta → PowerShell infection chain, and employing Windows anonymous pipes to exfiltrate data covertly and evade EDR/antivirus; the activity appears targeted and follows previous mass-phishing distributions of the same RAT.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
