Fast-Spreading, Complex Phishing Campaign Installs RATs
ID: cded42e1-1dc5-5183-a7e8-a45ae0e37bc7
STIX ID: report--cded42e1-1dc5-5183-a7e8-a45ae0e37bc7
Feed Name: Dark Reading
Date Published: 2025-08-25
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Fortinet Labs observed a global phishing campaign targeting Windows users across multiple sectors that lures victims to personalized spoof pages and delivers obfuscated JavaScript droppers (via UpCrypter) to deploy various RATs (PureHVNC, DCRat, Babylon RAT) and harvest credentials; the campaign uses anti-analysis techniques and in-memory execution, is rapidly growing, and defenders are advised to apply layered email/web/endpoint protections and PowerShell execution controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
