logo

ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins

ID: 90b520f8-18f9-5f15-8a42-591357bd3d8e

STIX ID: report--90b520f8-18f9-5f15-8a42-591357bd3d8e

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2024-04-08

Date Updated: 2026-04-27

...
...

Fortinet Labs describes a phishing-driven campaign attributed to the 8220 Gang that leverages SVG attachments and a layered delivery chain (BatCloak, ScrubCrypt) to install VenomRAT and multiple plugins (NanoCore, Remcos, XWorm, and a crypto wallet stealer). The attack uses advanced evasion and persistence techniques (AMSI/ETW bypass, scheduled tasks, process hollowing, steganography) and maintains encrypted C2 communications to fetch and execute plugins; the report includes C2 domains, URLs, and numerous file hashes as IOCs and notes Fortinet detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.